Automated Attack Discovery in TCP Congestion Control Using a Model-guided Approach
Samuel Jero, Md. Endadul Hoque, David R. Choffnes, Alan Mislove, Cristina Nita-Rotaru
Abstract
One of the most important goals of TCP is to ensure fairness and prevent congestion collapse by implementing congestion control. Various attacks against TCP congestion control have been reported over the years, most of which have been discovered through manual analysis. In this paper, we propose an automated method that combines the generality of implementation-agnostic fuzzing with the precision of runtime analysis to find attacks against implementations of TCP congestion control. It uses a model-guided approach to generate abstract attack strategies, by leveraging a state machine model of TCP congestion control to find vulnerable state machine paths that an attacker could exploit to increase or decrease the throughput of a connection to his advantage. These abstract strategies are then mapped to concrete attack strategies, which consist of sequences of actions such as injection or modification of acknowledgements and a logical time for injection. We design and implement a virtualized platform, TCPWN, that consists of a a proxy-based attack injector and a TCP congestion control state tracker that uses only network traffic to create and inject these concrete attack strategies. We evaluated 5 TCP implementations from 4 Linux distributions and Windows 8.1. Overall, we found 11 classes of attacks, of which 8 are new.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 6a86d644-b31f-4f46-b011-97954d47e891Cited by top-tier papers17
- Realtime Robust Malicious Traffic Detection via Frequency Domain AnalysisChuanpu Fu, Qi Li, Meng Shen, Ke XuCCS 2021 · 194 citations
- Automated Attack Synthesis by Extracting Finite State Machines from Protocol Specification DocumentsMaria Leonor Pacheco, Max von Hippel, Ben Weintraub, Dan Goldwasser et al.S&P 2022 · 58 citations
- TCP-Fuzz: Detecting Memory and Semantic Bugs in TCP Stacks with FuzzingYonghao Zou, Jia-Ju Bai, Jielong Zhou, Jianfeng Tan et al.USENIX ATC 2021 · 53 citations
- Invisible Probe: Timing Attacks with PCIe Congestion Side-channelMingtian Tan, Junpeng Wan, Zhe Zhou, Zhou LiS&P 2021 · 52 citations
- Off-Path TCP Exploits of the Mixed IPID AssignmentXuewei Feng, Chuanpu Fu, Qi Li, Kun Sun et al.CCS 2020 · 39 citations
Builds on1
Related papers
- DY Fuzzing: Formal Dolev-Yao Models Meet Cryptographic Protocol Fuzz TestingMax Ammann, Lucca Hirschi, Steve KremerS&P 2024 · 25 citations
- Linear-time Temporal Logic guided Greybox FuzzingRuijie Meng, Zhen Dong, Jialin Li, Ivan Beschastnikh et al.ICSE 2022 · 29 citations
- Stateful Greybox FuzzingJinsheng Ba, Marcel Böhme, Zahra Mirzamomen, Abhik RoychoudhuryUSENIX Security 2022
- StateFuzz: System Call-Based State-Aware Linux Driver FuzzingBodong Zhao, Zheming Li, Shisong Qin, Zheyu Ma et al.USENIX Security 2022
- PMTUD is not Panacea: Revisiting IP Fragmentation Attacks against TCPXuewei Feng, Qi Li, Kun Sun, Ke Xu et al.NDSS 2022
