SymTCP: Eluding Stateful Deep Packet Inspection with Automated Discrepancy Discovery
Zhongjie Wang, Shitong Zhu, Yue Cao, Zhiyun Qian, Chengyu Song, Srikanth V. Krishnamurthy, Kevin S. Chan, Tracy D. Braun
Abstract
A key characteristic of commonly deployed deep packet inspection (DPI) systems is that they implement a simplified state machine of the network stack that often differs from that of endhosts. The discrepancies between the two state machines have been exploited to bypass such DPI based middleboxes. However, most prior approaches to do so rely on manually crafted adversarial packets, which not only are labor-intensive but may not work well across a plurality of DPI-based middleboxes. Our goal in this work is to develop an automated way to craft candidate adversarial packets, targeting TCP implementations in particular. Our approach to achieving this goal hinges on the key insight that while the TCP state machines of DPI implementations are obscure, those of the endhosts are well established. Thus, in our system SYMTCP, using symbolic execution, we systematically explore the TCP implementation of an endhost, identifying candidate packets that can reach critical points in the code (e.g., which causes the packets to be accepted or dropped/ignored); such automatically identified packets are then fed through the DPI middlebox to determine if a discrepancy is induced and the middlebox can be eluded. We find that our approach is extremely effective. It can generate tens of thousands of candidate adversarial packets in less than an hour. When evaluating against multiple state-of-the-art DPI systems such as Zeek and Snort, as well as a state-level censorship system, viz. the Great Firewall of China, we identify not only previously known evasion strategies, but also novel ones that were never previously reported (e.g., involving the urgent pointer). The system can be extended easily towards other combinations of operating systems and DPI middleboxes, and serves as a valuable tool for testing future DPIs’ robustness against evasion attempts.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext b974938c-47ed-4433-9a64-3b62d2fb2a43Cited by top-tier papers17
- Censored Planet: An Internet-wide, Longitudinal Censorship ObservatoryRam Sundara Raman, Prerana Shenoy, Katharina Kohls, Roya EnsafiCCS 2020 · 68 citations
- TCP-Fuzz: Detecting Memory and Semantic Bugs in TCP Stacks with FuzzingYonghao Zou, Jia-Ju Bai, Jielong Zhou, Jianfeng Tan et al.USENIX ATC 2021 · 53 citations
- Weaponizing Middleboxes for TCP Reflected AmplificationKevin Bock, Abdulrahman Alaraj, Yair Fax, Kyle Hurley et al.USENIX Security 2021 · 49 citations
- Measuring and Evading Turkmenistan's Internet Censorship: A Case Study in Large-Scale Measurements of a Low-Penetration CountrySadia Nourin, Van Hong Tran, Xi Jiang, Kevin Bock et al.WWW 2023 · 25 citations
- ResolverFuzz: Automated Discovery of DNS Resolver Vulnerabilities with Query-Response FuzzingQifan Zhang, Xuesong Bai, Xiang Li, Haixin Duan et al.USENIX Security 2024 · 13 citations
Builds on7
- SOK: (State of) The Art of War: Offensive Techniques in Binary AnalysisYan Shoshitaishvili, Ruoyu Wang, Christopher Salls, Nick Stephens et al.S&P 2016 · 1,085 citations
- QSYM : A Practical Concolic Execution Engine Tailored for Hybrid FuzzingInsu Yun, Sangho Lee, Meng Xu, Yeongjin Jang et al.USENIX Security 2018 · 537 citations
- SymCerts: Practical Symbolic Execution for Exposing Noncompliance in X.509 Certificate Validation ImplementationsSze Yiu Chau, Omar Chowdhury, Md. Endadul Hoque, Huangyi Ge et al.S&P 2017 · 67 citations
- SFADiff: Automated Evasion Attacks and Fingerprinting Using Black-box Differential Automata LearningGeorge Argyros, Ioannis Stais, Suman Jana, Angelos D. Keromytis et al.CCS 2016 · 65 citations
- Geneva: Evolving Censorship Evasion StrategiesKevin Bock, George Hughey, Xiao Qiang, Dave LevinCCS 2019 · 60 citations
Related papers
- Themis: Ambiguity-Aware Network Intrusion Detection based on Symbolic Model ComparisonZhongjie Wang, Shitong Zhu, Keyu Man, Pengxiong Zhu et al.CCS 2021 · 6 citations
- Pryde: A Modular Generalizable Workflow for Uncovering Evasion Attacks Against Stateful Firewall DeploymentsSoo-Jin Moon, Milind Srivastava, Yves Bieri, Ruben Martins et al.S&P 2024 · 2 citations
- CircumVolve: Automated Discovery of Censorship Evasion Strategies Using Large Language ModelsAli Zohaib, Jackson Sippe, Jade Sheffey, Mingshi Wu et al.CCS 2026
- DeResistor: Toward Detection-Resistant Probing for Evasion of Internet CensorshipAbderrahmen Amich, Birhanu Eshete, Vinod Yegneswaran, Nguyen Phong HoangUSENIX Security 2023
- Technical Analysis of the Geedge Networks Firewall Source Code LeakAnna Ablove, Johnnie Walker, Ben Wolin, Niklas Niere et al.USENIX Security 2026
