USENIX Security2023Top-tier venue
Device Tracking via Linux's New TCP Source Port Selection Algorithm
Moshe Kol, Amit Klein, Yossi Gilad
Abstract
We describe a tracking technique for Linux devices, exploiting a new TCP source port generation mechanism recently introduced to the Linux kernel. This mechanism is based on an algorithm, standardized in RFC 6056, for boosting security by better randomizing port selection. Our technique detects collisions in a hash function used in the said algorithm, based on sampling TCP source ports generated in an attacker-prescribed manner. These hash collisions depend solely on a per-device key, and thus the set of collisions forms a device ID that allows tracking devices across browsers, browser privacy modes, containers, and IPv4/IPv6 networks (including some VPNs). It can distinguish among devices with identical hardware and software, and lasts until the device restarts. We implemented this technique and then tested it using tracking servers in two different locations and with Linux devices on various networks. We also tested it on an Android device that we patched to introduce the new port selection algorithm. The tracking technique works in real-life conditions, and we report detailed findings about it, including its dwell time, scalability, and success rate in different network types. We worked with the Linux kernel team to mitigate the exploit, resulting in a security patch introduced in May 2022 to the Linux kernel, and we provide recommendations for better securing the port selection algorithm in the paper.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3c1a3146-5fd6-4846-ae80-580d5ef1614bCited by top-tier papers2
- You Can Rand but You Can't Hide: A Holistic Security Analysis of Google Fuchsia's (and gVisor's) Network StackInon Kaplan, Ron Even, Amit KleinNDSS 2025
- Exploiting Sequence Number Leakage: TCP Hijacking in NAT-Enabled Wi-Fi NetworksYuxiang Yang, Xuewei Feng, Qi Li, Kun Sun et al.NDSS 2024
Builds on6
- DNS Cache-Based User TrackingAmit Klein, Benny PinkasNDSS 2019 · 34 citations
- Cross Layer Attacks and How to Use Them (for DNS Cache Poisoning, Device Tracking and More)Amit KleinS&P 2021 · 26 citations
- From IP ID to Device ID and KASLR BypassAmit Klein, Benny PinkasUSENIX Security 2019 · 25 citations
- Flaw Label: Exploiting IPv6 Flow LabelJonathan Berger, Amit Klein, Benny PinkasS&P 2020 · 11 citations
- Tales of Favicons and Caches: Persistent Tracking in Modern BrowsersKonstantinos Solomos, John Kristoff, Chris Kanich, Jason PolakisNDSS 2021
Related papers
- DRAWN APART: A Device Identification Technique based on Remote GPU FingerprintingTomer Laor, Naif Mehanna, Antonin Durey, Vitaly Dyadyuk et al.NDSS 2022
- Off-Path TCP Exploits of the Mixed IPID AssignmentXuewei Feng, Chuanpu Fu, Qi Li, Kun Sun et al.CCS 2020 · 39 citations
- Off-Path TCP Exploits: Global Rate Limit Considered DangerousYue Cao, Zhiyun Qian, Zhongjie Wang, Tuan Dao et al.USENIX Security 2016 · 74 citations
- Breaking Kernel Address Space Layout Randomization with Intel TSXYeongjin Jang, Sangho Lee, Taesoo KimCCS 2016 · 174 citations
- Clock Around the Clock: Time-Based Device FingerprintingIskander Sánchez-Rola, Igor Santos, Davide BalzarottiCCS 2018 · 91 citations
