SymTCP: Eluding Stateful Deep Packet Inspection with Automated Discrepancy Discovery
Zhongjie Wang, Shitong Zhu, Yue Cao, Zhiyun Qian, Chengyu Song, Srikanth V. Krishnamurthy, Kevin S. Chan, Tracy D. Braun
摘要
A key characteristic of commonly deployed deep packet inspection (DPI) systems is that they implement a simplified state machine of the network stack that often differs from that of endhosts. The discrepancies between the two state machines have been exploited to bypass such DPI based middleboxes. However, most prior approaches to do so rely on manually crafted adversarial packets, which not only are labor-intensive but may not work well across a plurality of DPI-based middleboxes. Our goal in this work is to develop an automated way to craft candidate adversarial packets, targeting TCP implementations in particular. Our approach to achieving this goal hinges on the key insight that while the TCP state machines of DPI implementations are obscure, those of the endhosts are well established. Thus, in our system SYMTCP, using symbolic execution, we systematically explore the TCP implementation of an endhost, identifying candidate packets that can reach critical points in the code (e.g., which causes the packets to be accepted or dropped/ignored); such automatically identified packets are then fed through the DPI middlebox to determine if a discrepancy is induced and the middlebox can be eluded. We find that our approach is extremely effective. It can generate tens of thousands of candidate adversarial packets in less than an hour. When evaluating against multiple state-of-the-art DPI systems such as Zeek and Snort, as well as a state-level censorship system, viz. the Great Firewall of China, we identify not only previously known evasion strategies, but also novel ones that were never previously reported (e.g., involving the urgent pointer). The system can be extended easily towards other combinations of operating systems and DPI middleboxes, and serves as a valuable tool for testing future DPIs’ robustness against evasion attempts.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper17
- Censored Planet: An Internet-wide, Longitudinal Censorship ObservatoryRam Sundara Raman, Prerana Shenoy, Katharina Kohls, Roya EnsafiCCS 2020 · 被引用 68 次
- TCP-Fuzz: Detecting Memory and Semantic Bugs in TCP Stacks with FuzzingYonghao Zou, Jia-Ju Bai, Jielong Zhou, Jianfeng Tan 等USENIX ATC 2021 · 被引用 53 次
- Weaponizing Middleboxes for TCP Reflected AmplificationKevin Bock, Abdulrahman Alaraj, Yair Fax, Kyle Hurley 等USENIX Security 2021 · 被引用 49 次
- Measuring and Evading Turkmenistan's Internet Censorship: A Case Study in Large-Scale Measurements of a Low-Penetration CountrySadia Nourin, Van Hong Tran, Xi Jiang, Kevin Bock 等WWW 2023 · 被引用 25 次
- ResolverFuzz: Automated Discovery of DNS Resolver Vulnerabilities with Query-Response FuzzingQifan Zhang, Xuesong Bai, Xiang Li, Haixin Duan 等USENIX Security 2024 · 被引用 13 次
它引用的顶会 Paper7
- SOK: (State of) The Art of War: Offensive Techniques in Binary AnalysisYan Shoshitaishvili, Ruoyu Wang, Christopher Salls, Nick Stephens 等S&P 2016 · 被引用 1,085 次
- QSYM : A Practical Concolic Execution Engine Tailored for Hybrid FuzzingInsu Yun, Sangho Lee, Meng Xu, Yeongjin Jang 等USENIX Security 2018 · 被引用 537 次
- SymCerts: Practical Symbolic Execution for Exposing Noncompliance in X.509 Certificate Validation ImplementationsSze Yiu Chau, Omar Chowdhury, Md. Endadul Hoque, Huangyi Ge 等S&P 2017 · 被引用 67 次
- SFADiff: Automated Evasion Attacks and Fingerprinting Using Black-box Differential Automata LearningGeorge Argyros, Ioannis Stais, Suman Jana, Angelos D. Keromytis 等CCS 2016 · 被引用 65 次
- Geneva: Evolving Censorship Evasion StrategiesKevin Bock, George Hughey, Xiao Qiang, Dave LevinCCS 2019 · 被引用 60 次
相关 Paper
- Themis: Ambiguity-Aware Network Intrusion Detection based on Symbolic Model ComparisonZhongjie Wang, Shitong Zhu, Keyu Man, Pengxiong Zhu 等CCS 2021 · 被引用 6 次
- Pryde: A Modular Generalizable Workflow for Uncovering Evasion Attacks Against Stateful Firewall DeploymentsSoo-Jin Moon, Milind Srivastava, Yves Bieri, Ruben Martins 等S&P 2024 · 被引用 2 次
- CircumVolve: Automated Discovery of Censorship Evasion Strategies Using Large Language ModelsAli Zohaib, Jackson Sippe, Jade Sheffey, Mingshi Wu 等CCS 2026
- DeResistor: Toward Detection-Resistant Probing for Evasion of Internet CensorshipAbderrahmen Amich, Birhanu Eshete, Vinod Yegneswaran, Nguyen Phong HoangUSENIX Security 2023
- Technical Analysis of the Geedge Networks Firewall Source Code LeakAnna Ablove, Johnnie Walker, Ben Wolin, Niklas Niere 等USENIX Security 2026
