USENIX Security2016Top-tier venue
Off-Path TCP Exploits: Global Rate Limit Considered Dangerous
Yue Cao, Zhiyun Qian, Zhongjie Wang, Tuan Dao, Srikanth V. Krishnamurthy, Lisa M. Marvel
Abstract
In this paper, we report a subtle yet serious side channel vulnerability (CVE-2016-5696) introduced in a recent TCP specification. The specification is faithfully implemented in Linux kernel version 3.6 (from 2012) and beyond, and affects a wide range of devices and hosts. In a nutshell, the vulnerability allows a blind off-path attacker to infer if any two arbitrary hosts on the Internet are communicating using a TCP connection. Further, if the connection is present, such an off-path attacker can also infer the TCP sequence numbers in use, from both sides of the connection; this in turn allows the attacker to cause connection termination and perform data injection attacks. We illustrate how the attack can be leveraged to disrupt or degrade the privacy guarantees of an anonymity network such as Tor, and perform web connection hijacking. Through extensive experiments, we show that the attack is fast and reliable. On average, it takes about 40 to 60 seconds to finish and the success rate is 88% to 97%. Finally, we propose changes to both the TCP specification and implementation to eliminate the root cause of the problem.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 21e0d7ad-ced1-4a2a-953b-0077073082a4Cited by top-tier papers27
- Realtime Robust Malicious Traffic Detection via Frequency Domain AnalysisChuanpu Fu, Qi Li, Meng Shen, Ke XuCCS 2021 · 194 citations
- TCP-Fuzz: Detecting Memory and Semantic Bugs in TCP Stacks with FuzzingYonghao Zou, Jia-Ju Bai, Jielong Zhou, Jianfeng Tan et al.USENIX ATC 2021 · 53 citations
- Automated Attack Discovery in TCP Congestion Control Using a Model-guided ApproachSamuel Jero, Md. Endadul Hoque, David R. Choffnes, Alan Mislove et al.NDSS 2018 · 46 citations
- Off-Path TCP Exploits of the Mixed IPID AssignmentXuewei Feng, Chuanpu Fu, Qi Li, Kun Sun et al.CCS 2020 · 39 citations
- Pythia: Remote Oracles for the MassesShin-Yeh Tsai, Mathias Payer, Yiying ZhangUSENIX Security 2019 · 37 citations
Related papers
- Off-Path TCP Exploit: How Wireless Routers Can Jeopardize Your SecretsWeiteng Chen, Zhiyun QianUSENIX Security 2018 · 35 citations
- Exploiting Sequence Number Leakage: TCP Hijacking in NAT-Enabled Wi-Fi NetworksYuxiang Yang, Xuewei Feng, Qi Li, Kun Sun et al.NDSS 2024
- Off-Path TCP Exploits: PMTUD Breaks TCP Connection Isolation in IP Address Sharing ScenariosXuewei Feng, Zhaoxi Li, Qi Li, Ziqiang Wang et al.CCS 2025
- Principled Unearthing of TCP Side Channel VulnerabilitiesYue Cao, Zhongjie Wang, Zhiyun Qian, Chengyu Song et al.CCS 2019 · 20 citations
- Off-Path TCP Hijacking in Wi-Fi Networks: A Packet-Size Side Channel AttackZiqiang Wang, Xuewei Feng, Qi Li, Kun Sun et al.NDSS 2025
