You Can Rand but You Can't Hide: A Holistic Security Analysis of Google Fuchsia's (and gVisor's) Network Stack
Inon Kaplan, Ron Even, Amit Klein
摘要
—This research is the first holistic analysis of the algorithmic security of the Google Fuchsia/gVisor network stack. Google Fuchsia is a new operating system developed by Google in a “clean slate” fashion. It is conjectured to eventually replace Android as an operating system for smartphones, tablets, and IoT devices. Fuchsia is already running in millions of Google Nest Hub consumer products. Google gVisor is an application kernel used by Google’s App Engine, Cloud Functions, Cloud ML Engine, Cloud Run, and Google Kubernetes Engine (GKE). Google Fuchsia uses the gVisor network stack code for its TCP/IP implementation. Wereportmultiple vulnerabilities in the algorithms used by Fuchsia/gVisor to populate network protocol header fields, specifically the TCP initial sequence number, TCP timestamp, TCP and UDP source ports, and IPv4/IPv6 fragment ID fields. In our holistic analysis, we show how a combination of multiple attacks results in the exposure of a PRNG seed and a hashing key used to generate the above fields. This enables an attacker to predict future values of the fields, which facilitates several network attacks. Our work focuses on web-based device tracking based on the stability and relative uniqueness of the PRNG seed and the hashing key. We demonstrate our device tracking techniques over the Internet with browsers running on multiple Fuchsia devices, in multiple browser modes (regular/privacy), and over multiple networks (including IPv4 vs. IPv6). Our tests verify that device tracking for Fuchsia is practical and yields a reliable device ID. We conclude with recommendations on mitigating the attacks and their root causes. We reported our findings to Google, which issued CVEs and patches for the security vulnerabilities we disclosed.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper9
- DNS Cache Poisoning Attack Reloaded: Revolutions with Side ChannelsKeyu Man, Zhiyun Qian, Zhongjie Wang, Xiaofeng Zheng 等CCS 2020 · 被引用 62 次
- JavaScript Template Attacks: Automatically Inferring Host Information for Targeted ExploitsMichael Schwarz, Florian Lackner, Daniel GrussNDSS 2019 · 被引用 57 次
- Off-Path TCP Exploits of the Mixed IPID AssignmentXuewei Feng, Chuanpu Fu, Qi Li, Kun Sun 等CCS 2020 · 被引用 39 次
- DNS Cache-Based User TrackingAmit Klein, Benny PinkasNDSS 2019 · 被引用 34 次
- Cross Layer Attacks and How to Use Them (for DNS Cache Poisoning, Device Tracking and More)Amit KleinS&P 2021 · 被引用 26 次
相关 Paper
- Device Tracking via Linux's New TCP Source Port Selection AlgorithmMoshe Kol, Amit Klein, Yossi GiladUSENIX Security 2023
- Flaw Label: Exploiting IPv6 Flow LabelJonathan Berger, Amit Klein, Benny PinkasS&P 2020 · 被引用 11 次
- From IP ID to Device ID and KASLR BypassAmit Klein, Benny PinkasUSENIX Security 2019 · 被引用 25 次
- Bleem: Packet Sequence Oriented Fuzzing for Protocol ImplementationsZhengxiong Luo, Junze Yu, Feilong Zuo, Jianzhong Liu 等USENIX Security 2023
- Call Me Back!: Attacks on System Server and System Apps in Android through Synchronous CallbackKai Wang, Yuqing Zhang, Peng LiuCCS 2016 · 被引用 22 次
