WAVED: Principled Identification of Off-Path Exploitable Weak Verifications within the TCP/IP Protocol Suite
Yizhou Zhao, Xuewei Feng, Min Li, Ke Xu
摘要
Off-path exploits targeting the fundamental TCP/IP protocol suite pose significant threats to the security of the Internet infrastructure. In particular, weak verifications of received payloads—arising from the lack of reliable information to validate or implementation flaws within the suite—lead to vulnerabilities that attackers can exploit to manipulate traffic, induce data loss, and disrupt services on victim servers. In this paper, we present the first systematic study of these vulnerabilities and introduce WAVED, a framework for identifying off-path exploitable weak verifications within the TCP/IP protocol suite implementation. At the core of WAVED, we develop a flow-, context-, and field-sensitive pointer analysis tailored to the TCP/IP kernel, and construct a Taint Propagation Graph (TPG) to model and trace data flow within the stack. By modeling byte-granularity taint propagation across diverse arithmetic operations, our approach can accurately locate specific input bytes associated with each constraint. Furthermore, direction-sensitive taint information is computed to accurately capture and differentiate the strength of constraints imposed by alternative branch outcomes, thereby significantly outperforming traditional byte-insensitive and direction-insensitive analyses. We evaluate WAVED on IPv4 and IPv6 across Linux 5.15, Linux 6.8, and FreeBSD 14.1. It precisely uncovers weak verifications leading to semantic vulnerabilities in TCP/IP and reveals 14 previously unknown vulnerabilities. We have responsibly disclosed these vulnerabilities to the affected OS vendors and have received acknowledgments from the Linux community.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper16
- Off-Path TCP Exploits: Global Rate Limit Considered DangerousYue Cao, Zhiyun Qian, Zhongjie Wang, Tuan Dao 等USENIX Security 2016 · 被引用 74 次
- Domain Validation++ For MitM-Resilient PKIMarkus Brandt, Tianxiang Dai, Amit Klein, Haya Schulmann 等CCS 2018 · 被引用 71 次
- DNS Cache Poisoning Attack Reloaded: Revolutions with Side ChannelsKeyu Man, Zhiyun Qian, Zhongjie Wang, Xiaofeng Zheng 等CCS 2020 · 被引用 62 次
- TCP-Fuzz: Detecting Memory and Semantic Bugs in TCP Stacks with FuzzingYonghao Zou, Jia-Ju Bai, Jielong Zhou, Jianfeng Tan 等USENIX ATC 2021 · 被引用 53 次
- Off-Path TCP Exploits of the Mixed IPID AssignmentXuewei Feng, Chuanpu Fu, Qi Li, Kun Sun 等CCS 2020 · 被引用 39 次
相关 Paper
- Bond: Constraint-Directed Fuzzing for Automated Validation of Taint Analysis Results in Linux-based IoT FirmwareJiaqian Peng, Puzhuo Liu, Kai Cheng, Zhaoteng Yan 等USENIX Security 2026
- ZIPPER: Static Taint Analysis for PHP Applications with Precision and EfficiencyXinyi Wang, Yeting Li, Jie Lu, Shizhe Cui 等USENIX Security 2025
- CoBrA: Context-, Branch-sensitive Static Analysis for Detecting Taint-style Vulnerabilities in PHP Web ApplicationsYichao Xu, Mingqing Kang, Neil Thimmaiah, Rigel Gjomemo 等ICSE 2026
- PacDroid: A Pointer-Analysis-Centric Framework for Security Vulnerabilities in Android AppsMenglong Chen, Tian Tan, Minxue Pan, Yue LiICSE 2025 · 被引用 1 次
- Principled Unearthing of TCP Side Channel VulnerabilitiesYue Cao, Zhongjie Wang, Zhiyun Qian, Chengyu Song 等CCS 2019 · 被引用 20 次
