Crossing the Streams: SSH Plaintext Recovery via a Common Compression Context in Multiplexed Channels
Fabian Bäumer, Marcus Brinkmann
Abstract
SSH is the standard protocol for secure remote administration of servers. At the transport layer, SSH uses the Binary Packet Protocol (BPP) for encrypted and authenticated communication. Above this, the SSH Connection Protocol multiplexes one or more logical channels over a single connection, supporting interactive shells, port forwarding, and related functionality.
We show that SSH channel multiplexing creates a previously unrecognized compression side channel: all channels on a connection share the same compression context. When compression is enabled, an attacker can inject partially chosen plaintext into a channel and observe the length of the resulting ciphertext on the network. This enables an adaptive chosen-plaintext attack that recovers secrets from one channel by interacting with another. While related attacks such as CRIME and BREACH have been studied extensively for HTTP over TLS, this is, to our knowledge, the first compression side-channel attack on SSH and the first SSH analysis to consider a combined passive eavesdropper and web attacker threat model.
We further demonstrate the attack in three different application scenarios and evaluate its effectiveness under varying levels of protocol noise. We find that, in the lowest-noise scenario, an 8character secret over a 26-letter alphabet can be recovered using at most 276 guesses. Finally, we analyze the SSH ecosystem for compression support and other implementation characteristics that influence the practical efficacy of the attack.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 9e25ebe6-acab-4166-a6e1-8c5848b1d815Builds on12
- Beauty and the Burst: Remote Identification of Encrypted Video StreamsRoei Schuster, Vitaly Shmatikov, Eran TromerUSENIX Security 2017 · 205 citations
- Transcript Collision Attacks: Breaking Authentication in TLS, IKE and SSHKarthikeyan Bhargavan, Gaëtan LeurentNDSS 2016 · 128 citations
- A Surfeit of SSH Cipher SuitesMartin R. Albrecht, Jean Paul Degabriele, Torben Brandt Hansen, Kenneth G. PatersonCCS 2016 · 36 citations
- Terrapin Attack: Breaking SSH Channel Integrity By Sequence Number ManipulationFabian Bäumer, Marcus Brinkmann, Jörg SchwenkUSENIX Security 2024 · 15 citations
- Injection Attacks Against End-to-End Encrypted ApplicationsAndrés Fábrega, Carolina Ortega Pérez, Armin Namavari, Ben Nassi et al.S&P 2024 · 9 citations
Related papers
- Criminology: Refined Techniques for Compression Side-Channel AttacksYuanming Song, Lenka Mareková, Kenneth G. PatersonCCS 2026
- "Make Sure DSA Signing Exponentiations Really are Constant-Time"Cesar Pereida García, Billy Bob Brumley, Yuval YaromCCS 2016 · 93 citations
- Passive SSH Key Compromise via LatticesKeegan Ryan, Kaiwen He, George Arnold Sullivan, Nadia HeningerCCS 2023 · 8 citations
- DBREACH: Stealing from Databases Using Compression Side ChannelsMathew Hogan, Yan Michalevsky, Saba EskandarianS&P 2023
- Lend Me Your Ear: Passive Remote Physical Side Channels on PCsDaniel Genkin, Noam Nissan, Roei Schuster, Eran TromerUSENIX Security 2022
