Pryde: A Modular Generalizable Workflow for Uncovering Evasion Attacks Against Stateful Firewall Deployments
Soo-Jin Moon, Milind Srivastava, Yves Bieri, Ruben Martins, Vyas Sekar
摘要
Stateful firewalls (SFW) play a critical role in securing our network infrastructure. Incorrect implementation of the intended stateful semantics can lead to evasion opportunities, even if firewall rules are configured correctly. Uncovering these opportunities is challenging due to the (1) black-box and proprietary nature of firewalls; (2) diversity of deployments; and (3) complex stateful semantics. To tackle these challenges, we present Pryde. Pryde uses a modular model-guided workflow that generalizes across black-box firewall implementations and deployment-specific settings to generate evasion attacks. Pryde infers a behavioral model of the stateful firewall in the presence of potentially non-TCP-compliant packet sequences. It uses this model in conjunction with attacker capabilities and victim behavior to synthesize custom evasion attacks. Using Pryde, we identify more than 6,000 unique attacks against 4 popular firewalls and 4 host networking stacks, many of which cannot be uncovered by prior work on censorship circumvention and black-box fuzzing.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- Fingerprinting Deep Packet Inspection Devices by their AmbiguitiesDiwen Xue, Armin Huremagic, Wayne Wang, Ram Sundara Raman 等CCS 2025
- From Intention to Practice: Towards Systematic Validation of NIDS Rule EnforcementHuan Liu, Haoyu Chen, Biang Xu, Jingyao Zhou 等NSDI 2026
- Generating Precise Format Specification for Network Protocols Through Adversarial LLM InteractionsHengdi Ye, Bing Shui, Jielun Wu, Yufan Zhou 等USENIX Security 2026
它引用的顶会 Paper10
- Understanding the Mirai BotnetManos Antonakakis, Tim April, Michael D. Bailey, Matt Bernhard 等USENIX Security 2017 · 被引用 2,003 次
- SoK: Security Evaluation of Home-Based IoT DeploymentsOmar Alrawi, Chaz Lever, Manos Antonakakis, Fabian MonroseS&P 2019 · 被引用 411 次
- Geneva: Evolving Censorship Evasion StrategiesKevin Bock, George Hughey, Xiao Qiang, Dave LevinCCS 2019 · 被引用 60 次
- NetSMC: A Custom Symbolic Model Checker for Stateful Network VerificationYifei Yuan, Soo-Jin Moon, Sahil Uppal, Limin Jia 等NSDI 2020 · 被引用 42 次
- Noncompliance as Deviant Behavior: An Automated Black-box Noncompliance Checker for 4G LTE Cellular DevicesSyed Rafiul Hussain, Imtiaz Karim, Abdullah Al Ishtiaq, Omar Chowdhury 等CCS 2021 · 被引用 41 次
相关 Paper
- SymTCP: Eluding Stateful Deep Packet Inspection with Automated Discrepancy DiscoveryZhongjie Wang, Shitong Zhu, Yue Cao, Zhiyun Qian 等NDSS 2020
- NetHide: Secure and Practical Network Topology ObfuscationRoland Meier, Petar Tsankov, Vincent Lenders, Laurent Vanbever 等USENIX Security 2018 · 被引用 84 次
- SFADiff: Automated Evasion Attacks and Fingerprinting Using Black-box Differential Automata LearningGeorge Argyros, Ioannis Stais, Suman Jana, Angelos D. Keromytis 等CCS 2016 · 被引用 65 次
- Inferring Firewall Rules by Cache Side-channel Analysis in Network Function VirtualizationYoungjoo Shin, Dongyoung Koo, Junbeom HurINFOCOM 2020 · 被引用 8 次
- A Wolf in Sheep's Clothing: Practical Black-box Adversarial Attacks for Evading Learning-based Windows Malware Detection in the WildXiang Ling, Zhiyu Wu, Bin Wang, Wei Deng 等USENIX Security 2024 · 被引用 13 次
