Cross Layer Attacks and How to Use Them (for DNS Cache Poisoning, Device Tracking and More)
Amit Klein
摘要
We analyze the prandom pseudo random number generator (PRNG) in use in the Linux kernel (which is the kernel of the Linux operating system, as well as of Android) and demonstrate that this PRNG is weak. The prandom PRNG is in use by many "consumers" in the Linux kernel. We focused on three consumers at the network level – the UDP source port generation algorithm, the IPv6 flow label generation algorithm and the IPv4 ID generation algorithm. The flawed prandom PRNG is shared by all these consumers, which enables us to mount "cross layer attacks" against the Linux kernel. In these attacks, we infer the internal state of the prandom PRNG from one OSI layer, and use it to either predict the values of the PRNG employed by the other OSI layer, or to correlate it to an internal state of the PRNG inferred from the other protocol.Using this approach we can mount a very efficient DNS cache poisoning attack against Linux. We collect TCP/IPv6 flow label values, or UDP source ports, or TCP/IPv4 IP ID values, reconstruct the internal PRNG state, then predict an outbound DNS query UDP source port, which speeds up the attack by a factor of x3000 to x6000. This attack works remotely, but can also be mounted locally, across Linux users and across containers, and (depending on the stub resolver) can poison the cache with an arbitrary DNS record. Additionally, we can identify and track Linux and Android devices – we collect TCP/IPv6 flow label values and/or UDP source port values and/or TCP/IPv4 ID fields, reconstruct the PRNG internal state and correlate this new state to previously extracted PRNG states to identify the same device.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper15
- The Hijackers Guide To The Galaxy: Off-Path Taking Over Internet ResourcesTianxiang Dai, Philipp Jeitner, Haya Schulmann, Michael WaidnerUSENIX Security 2021 · 被引用 22 次
- From IP to transport and beyond: cross-layer attacks against applicationsTianxiang Dai, Philipp Jeitner, Haya Schulmann, Michael WaidnerSIGCOMM 2021 · 被引用 14 次
- ResolverFuzz: Automated Discovery of DNS Resolver Vulnerabilities with Query-Response FuzzingQifan Zhang, Xuesong Bai, Xiang Li, Haixin Duan 等USENIX Security 2024 · 被引用 13 次
- Rethinking the Security Threats of Stale DNS Glue RecordsYunyi Zhang, Baojun Liu, Haixin Duan, Min Zhang 等USENIX Security 2024 · 被引用 9 次
- Should I Trust You? Rethinking the Principle of Zone-Based Isolation DNS Bailiwick CheckingYuxiao Wu, Yunyi Zhang, Chaoyi Lu, Baojun LiuNDSS 2026 · 被引用 2 次
它引用的顶会 Paper5
- Network Hygiene, Incentives, and Regulation: Deployment of Source Address Validation in the InternetMatthew J. Luckie, Robert Beverly, Ryan Koga, Ken Keys 等CCS 2019 · 被引用 89 次
- Domain Validation++ For MitM-Resilient PKIMarkus Brandt, Tianxiang Dai, Amit Klein, Haya Schulmann 等CCS 2018 · 被引用 71 次
- DNS Cache-Based User TrackingAmit Klein, Benny PinkasNDSS 2019 · 被引用 34 次
- Flaw Label: Exploiting IPv6 Flow LabelJonathan Berger, Amit Klein, Benny PinkasS&P 2020 · 被引用 11 次
- Poison Over Troubled Forwarders: A Cache Poisoning Attack Targeting DNS Forwarding DevicesXiaofeng Zheng, Chaoyi Lu, Jian Peng, Qiushi Yang 等USENIX Security 2020
相关 Paper
- DNS Cache Poisoning Attack: Resurrections with Side ChannelsKeyu Man, Xin'an Zhou, Zhiyun QianCCS 2021 · 被引用 33 次
- Device Tracking via Linux's New TCP Source Port Selection AlgorithmMoshe Kol, Amit Klein, Yossi GiladUSENIX Security 2023
- DNS Cache Poisoning Attack Reloaded: Revolutions with Side ChannelsKeyu Man, Zhiyun Qian, Zhongjie Wang, Xiaofeng Zheng 等CCS 2020 · 被引用 62 次
- DNS Cache Poisoning Like it’s 2006Omer Ben-Simhon, Amit KleinUSENIX Security 2026
- From IP ID to Device ID and KASLR BypassAmit Klein, Benny PinkasUSENIX Security 2019 · 被引用 25 次
