USENIX Security2019Top-tier venue
From IP ID to Device ID and KASLR Bypass
Amit Klein, Benny Pinkas
Abstract
IP headers include a 16-bit ID field. Our work examines the generation of this field in Windows (versions 8 and higher), Linux and Android, and shows that the IP ID field enables remote servers to assign a unique ID to each device and thus be able to identify subsequent transmissions sent from that device. This identification works across all browsers and over network changes. In modern Linux and Android versions, this field leaks a kernel address, thus we also break KASLR. Our work includes reverse-engineering of the Windows IP ID generation code, and a cryptanalysis of this code and of the Linux kernel IP ID generation code. It provides practical techniques to partially extract the key used by each of these algorithms, overcoming different implementation issues, and observing that this key can identify individual devices. We deployed a demo (for Windows) showing that key extraction and machine fingerprinting works in the wild, and tested it from networks around the world.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext babdac3d-9803-44f7-93a8-8587be24383cCited by top-tier papers12
- Fragment and Forge: Breaking Wi-Fi Through Frame Aggregation and FragmentationMathy VanhoefUSENIX Security 2021 · 48 citations
- TCP Spoofing: Reliable Payload Transmission Past the Spoofed TCP HandshakeYepeng Pan, Christian RossowS&P 2024 · 15 citations
- Flaw Label: Exploiting IPv6 Flow LabelJonathan Berger, Amit Klein, Benny PinkasS&P 2020 · 11 citations
- KASLR in the age of MicroVMsBenjamin Holmes, Jason Waterman, Dan WilliamsEuroSys 2022 · 5 citations
- Remote Memory-Deduplication AttacksMartin Schwarzl, Erik Kraft, Moritz Lipp, Daniel GrussNDSS 2022
Builds on5
- (Cross-)Browser Fingerprinting via OS and Hardware Level FeaturesYinzhi Cao, Song Li, Erik WijmansNDSS 2017 · 199 citations
- Tracking Mobile Web Users Through Motion Sensors: Attacks and DefensesAnupam Das, Nikita Borisov, Matthew CaesarNDSS 2016 · 145 citations
- FP-STALKER: Tracking Browser Fingerprint EvolutionsAntoine Vastel, Pierre Laperdrix, Walter Rudametkin, Romain RouvoyS&P 2018 · 117 citations
- Clock Around the Clock: Time-Based Device FingerprintingIskander Sánchez-Rola, Igor Santos, Davide BalzarottiCCS 2018 · 91 citations
- DNS Cache-Based User TrackingAmit Klein, Benny PinkasNDSS 2019 · 34 citations
Related papers
- Device Tracking via Linux's New TCP Source Port Selection AlgorithmMoshe Kol, Amit Klein, Yossi GiladUSENIX Security 2023
- Cross Layer Attacks and How to Use Them (for DNS Cache Poisoning, Device Tracking and More)Amit KleinS&P 2021 · 26 citations
- You Can Rand but You Can't Hide: A Holistic Security Analysis of Google Fuchsia's (and gVisor's) Network StackInon Kaplan, Ron Even, Amit KleinNDSS 2025
- Off-Path TCP Exploits of the Mixed IPID AssignmentXuewei Feng, Chuanpu Fu, Qi Li, Kun Sun et al.CCS 2020 · 39 citations
- Breaking Kernel Address Space Layout Randomization with Intel TSXYeongjin Jang, Sangho Lee, Taesoo KimCCS 2016 · 174 citations
