USENIX Security2026Top-tier venue
WAVED: Principled Identification of Off-Path Exploitable Weak Verifications within the TCP/IP Protocol Suite
Yizhou Zhao, Xuewei Feng, Min Li, Ke Xu
Abstract
Off-path exploits targeting the fundamental TCP/IP protocol suite pose significant threats to the security of the Internet infrastructure. In particular, weak verifications of received payloads—arising from the lack of reliable information to validate or implementation flaws within the suite—lead to vulnerabilities that attackers can exploit to manipulate traffic, induce data loss, and disrupt services on victim servers. In this paper, we present the first systematic study of these vulnerabilities and introduce WAVED, a framework for identifying off-path exploitable weak verifications within the TCP/IP protocol suite implementation. At the core of WAVED, we develop a flow-, context-, and field-sensitive pointer analysis tailored to the TCP/IP kernel, and construct a Taint Propagation Graph (TPG) to model and trace data flow within the stack. By modeling byte-granularity taint propagation across diverse arithmetic operations, our approach can accurately locate specific input bytes associated with each constraint. Furthermore, direction-sensitive taint information is computed to accurately capture and differentiate the strength of constraints imposed by alternative branch outcomes, thereby significantly outperforming traditional byte-insensitive and direction-insensitive analyses. We evaluate WAVED on IPv4 and IPv6 across Linux 5.15, Linux 6.8, and FreeBSD 14.1. It precisely uncovers weak verifications leading to semantic vulnerabilities in TCP/IP and reveals 14 previously unknown vulnerabilities. We have responsibly disclosed these vulnerabilities to the affected OS vendors and have received acknowledgments from the Linux community.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext ca4e99e1-72e2-4bb5-a241-68fddf35636aBuilds on16
- Off-Path TCP Exploits: Global Rate Limit Considered DangerousYue Cao, Zhiyun Qian, Zhongjie Wang, Tuan Dao et al.USENIX Security 2016 · 74 citations
- Domain Validation++ For MitM-Resilient PKIMarkus Brandt, Tianxiang Dai, Amit Klein, Haya Schulmann et al.CCS 2018 · 71 citations
- DNS Cache Poisoning Attack Reloaded: Revolutions with Side ChannelsKeyu Man, Zhiyun Qian, Zhongjie Wang, Xiaofeng Zheng et al.CCS 2020 · 62 citations
- TCP-Fuzz: Detecting Memory and Semantic Bugs in TCP Stacks with FuzzingYonghao Zou, Jia-Ju Bai, Jielong Zhou, Jianfeng Tan et al.USENIX ATC 2021 · 53 citations
- Off-Path TCP Exploits of the Mixed IPID AssignmentXuewei Feng, Chuanpu Fu, Qi Li, Kun Sun et al.CCS 2020 · 39 citations
Related papers
- Bond: Constraint-Directed Fuzzing for Automated Validation of Taint Analysis Results in Linux-based IoT FirmwareJiaqian Peng, Puzhuo Liu, Kai Cheng, Zhaoteng Yan et al.USENIX Security 2026
- ZIPPER: Static Taint Analysis for PHP Applications with Precision and EfficiencyXinyi Wang, Yeting Li, Jie Lu, Shizhe Cui et al.USENIX Security 2025
- CoBrA: Context-, Branch-sensitive Static Analysis for Detecting Taint-style Vulnerabilities in PHP Web ApplicationsYichao Xu, Mingqing Kang, Neil Thimmaiah, Rigel Gjomemo et al.ICSE 2026
- PacDroid: A Pointer-Analysis-Centric Framework for Security Vulnerabilities in Android AppsMenglong Chen, Tian Tan, Minxue Pan, Yue LiICSE 2025 · 1 citation
- Principled Unearthing of TCP Side Channel VulnerabilitiesYue Cao, Zhongjie Wang, Zhiyun Qian, Chengyu Song et al.CCS 2019 · 20 citations
