ALPACA: Application Layer Protocol Confusion - Analyzing and Mitigating Cracks in TLS Authentication
Marcus Brinkmann, Christian Dresen, Robert Merget, Damian Poddebniak, Jens Müller, Juraj Somorovsky, Jörg Schwenk, Sebastian Schinzel
摘要
TLS is widely used to add confidentiality, authenticity and integrity to application layer protocols such as HTTP, SMTP, IMAP, POP3, and FTP. However, TLS does not bind a TCP connection to the intended application layer protocol. This allows a man-in-the-middle attacker to redirect TLS traffic to a different TLS service endpoint on another IP address and/or port. For example, if subdomains share a wildcard certificate, an attacker can redirect traffic from one subdomain to another, resulting in a valid TLS session. This breaks the authentication of TLS and cross-protocol attacks may be possible where the behavior of one service may compromise the security of the other at the application layer. In this paper, we investigate cross-protocol attacks on TLS in general and conduct a systematic case study on web servers, redirecting HTTPS requests from a victim's web browser to SMTP, IMAP, POP3, and FTP servers. We show that in realistic scenarios, the attacker can extract session cookies and other private user data or execute arbitrary JavaScript in the context of the vulnerable web server, therefore bypassing TLS and web application security. We evaluate the real-world attack surface of web browsers and widely-deployed email and FTP servers in lab experiments and with internet-wide scans. We find that 1.4M web servers are generally vulnerable to cross-protocol attacks, i.e., TLS application data confusion is possible. Of these, 114k web servers can be attacked using an exploitable application server. Finally, we discuss the effectiveness of TLS extensions such as Application Layer Protocol Negotiation (ALPN) and Server Name Indiciation (SNI) in mitigating these and other cross-protocol attacks.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper9
- A Unified Symbolic Analysis of WireGuardPascal Lafourcade, Dhekra Mahmoud, Sylvain RuhaultNDSS 2024
- STEK Sharing is Not Caring: Bypassing TLS Authentication in Web Servers using Session TicketsSven Hebrok, Tim Leonhard Storm, Felix Matthias Cramer, Maximilian Radoy 等USENIX Security 2025
- Towards Internet-Based State Learning of TLS State MachinesMarcel Maehren, Nurullah Erinola, Robert Merget, Jörg Schwenk 等USENIX Security 2025
- We Really Need to Talk About Session Tickets: A Large-Scale Analysis of Cryptographic Dangers with TLS Session TicketsSven Hebrok, Simon Nachtigall, Marcel Maehren, Nurullah Erinola 等USENIX Security 2023
- Cross-Origin Web Attacks via HTTP/2 Server Push and Signed HTTP ExchangePinji Chen, Jianjun Chen, Mingming Zhang, Qi Wang 等NDSS 2025
它引用的顶会 Paper6
- Tranco: A Research-Oriented Top Sites Ranking Hardened Against ManipulationVictor Le Pochat, Tom van Goethem, Samaneh Tajalizadehkhoob, Maciej Korczynski 等NDSS 2019 · 被引用 826 次
- DROWN: Breaking TLS Using SSLv2Nimrod Aviram, Sebastian Schinzel, Juraj Somorovsky, Nadia Heninger 等USENIX Security 2016 · 被引用 192 次
- TLS in the Wild: An Internet-wide Analysis of TLS-based Protocols for Electronic CommunicationRalph Holz, Johanna Amann, Olivier Mehani, Mohamed Ali Kâafar 等NDSS 2016 · 被引用 117 次
- Same-Origin Policy: Evaluation in Modern BrowsersJörg Schwenk, Marcus Niemietz, Christian MainkaUSENIX Security 2017 · 被引用 52 次
- SoK: Exploiting Network PrintersJens Müller, Vladislav Mladenov, Juraj Somorovsky, Jörg SchwenkS&P 2017 · 被引用 31 次
相关 Paper
- Opossum Attack: Application Layer Desynchronization using Opportunistic TLSRobert Merget, Nurullah Erinola, Marcel Maehren, Lukas Knittel 等USENIX Security 2026
- Why TLS is better without STARTTLS: A Security Analysis of STARTTLS in the Email ContextDamian Poddebniak, Fabian Ising, Hanno Böck, Sebastian SchinzelUSENIX Security 2021 · 被引用 25 次
- Talking with Familiar Strangers: An Empirical Study on HTTPS Context Confusion AttacksMingming Zhang, Xiaofeng Zheng, Kaiwen Shen, Ziqiao Kong 等CCS 2020 · 被引用 15 次
- Postcards from the Post-HTTP World: Amplification of HTTPS Vulnerabilities in the Web EcosystemStefano Calzavara, Riccardo Focardi, Matús Nemec, Alvise Rabitti 等S&P 2019 · 被引用 24 次
- A Multifaceted Study on the Use of TLS and Auto-detect in Email EcosystemsKa Fun Tang, Che Wei Tu, Sui Ling Angela Mak, Sze Yiu ChauNDSS 2025
