USENIX Security2024Top-tier venue
You Can Obfuscate, but You Cannot Hide: CrossPoint Attacks against Network Topology Obfuscation
Xuanbo Huang, Kaiping Xue, Lutong Chen, Mingrui Ai, Huancheng Zhou, Bo Luo, Guofei Gu, Qibin Sun
Abstract
Link-flooding attacks (LFAs) may disrupt Internet connections in targeted areas by flooding specific links. One effective mitigation strategy against these attacks is network topology obfuscation (NTO), which aims to obscure the network map and conceal critical links, preventing attackers from identifying bottleneck links. However, we argue that the attackers can still discover critical links in the presence of NTO defenses. In this paper, we introduce the CrossPoint attacks to escape the security protections of state-of-the-art NTO defenses by exploiting two network traffic features: correlated congestion and statistical disparities. Although NTO defenses create a complex and seemingly robust virtual topology, distinct information is still discoverable due to conflicting design objectives and inherent features of the Internet, resulting in novel side channels. Through comprehensive experiments, including a measurement study on the Internet, we demonstrate CrossPoint attacks' high success rate (80%-95%), minor overhead (10%-20%), as well as attack stealthiness and feasibility.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 37eb4810-203e-49f6-8377-fa2452b03b61Cited by top-tier papers1
Ask how each one uses itBuilds on12
- Realtime Robust Malicious Traffic Detection via Frequency Domain AnalysisChuanpu Fu, Qi Li, Meng Shen, Ke XuCCS 2021 · 194 citations
- SPIFFY: Inducing Cost-Detectability Tradeoffs for Persistent Link-Flooding AttacksMin Suk Kang, Virgil D. Gligor, Vyas SekarNDSS 2016 · 123 citations
- Ripple: A Programmable, Decentralized Link-Flooding Defense Against Adaptive AdversariesJiarong Xing, Wenqing Wu, Ang ChenUSENIX Security 2021 · 100 citations
- NetHide: Secure and Practical Network Topology ObfuscationRoland Meier, Petar Tsankov, Vincent Lenders, Laurent Vanbever et al.USENIX Security 2018 · 84 citations
- Routing Around Congestion: Defeating DDoS Attacks and Adverse Network Conditions via Reactive BGP RoutingJared M. Smith, Max SchuchardS&P 2018 · 71 citations
Related papers
- EqualNet: A Secure and Practical Defense for Long-term Network Topology ObfuscationJinwoo Kim, Eduard Marin, Mauro Conti, Seungwon ShinNDSS 2022
- Mew: Enabling Large-Scale and Dynamic Link-Flooding Defenses on Programmable SwitchesHuancheng Zhou, Sungmin Hong, Yangyang Liu, Xiapu Luo et al.S&P 2023
- On the Feasibility of Rerouting-Based DDoS DefensesMuoi Tran, Min Suk Kang, Hsu-Chun Hsiao, Wei-Hsuan Chiang et al.S&P 2019 · 39 citations
- ditto: WAN Traffic Obfuscation at Line RateRoland Meier, Vincent Lenders, Laurent VanbeverNDSS 2022
- MUFFLER: Secure Tor Traffic Obfuscation with Dynamic Connection Shuffling and SplittingMinjae Seo, Myoungsung You, Jaehan Kim, Taejune Park et al.INFOCOM 2025
