Finding SSH Strict Key Exchange Violations by State Learning
Fabian Bäumer, Marcel Maehren, Marcus Brinkmann, Jörg Schwenk
摘要
SSH is an important protocol for secure remote shell access to servers on the Internet. At USENIX 2024, Bäumer et al. presented the Terrapin attack on SSH, which relies on the attacker injecting optional messages during the key exchange. To mitigate this attack, SSH vendors adopted an extension developed by OpenSSH called strict key exchange (''strict KEX''). With strict KEX, optional messages are forbidden during the handshake, preventing the attack. In practice, this should simplify the state machine of an SSH handshake to a linear message flow similar to that of TLS. In this work, we analyze the design, implementation, and security of strict KEX in popular SSH servers, using black-box state learning, which can uncover the hidden state machine of an implementation. In practice, it is limited by the number of learned messages and the complexity of the state machine. Thus, learning the complete state machine of SSH is infeasible. Previous research on SSH, therefore, excluded optional messages, learning only a partial state machine. However, these messages are a critical part of the Terrapin attack. We propose to instead learn the complete state machine of the handshake phase of an SSH server, but with strict KEX enabled. We investigate the security of ten SSH implementations supporting strict KEX for up to five key exchange algorithms. In total, we learn 33 state machines, revealing significant differences in the implementations. We show that seven implementations violate the strict KEX specification and find two critical security vulnerabilities. One results in a rogue session attack in the proprietary Tectia SSH implementation. Another affects the official SSH implementation of the Erlang Open Telecom Platform, and enables unauthenticated remote code execution in the security context of the SSH server.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- Hop: A Modern Transport and Remote Access ProtocolPaul Flammarion, George Hosono, Wilson Nguyen, Laura Bauman 等USENIX Security 2026
- Crossing the Streams: SSH Plaintext Recovery via a Common Compression Context in Multiplexed ChannelsFabian Bäumer, Marcus BrinkmannCCS 2026
它引用的顶会 Paper17
- Systematic Fuzzing and Testing of TLS LibrariesJuraj SomorovskyCCS 2016 · 被引用 136 次
- Transcript Collision Attacks: Breaking Authentication in TLS, IKE and SSHKarthikeyan Bhargavan, Gaëtan LeurentNDSS 2016 · 被引用 128 次
- HVLearn: Automated Black-Box Analysis of Hostname Verification in SSL/TLS ImplementationsSuphannee Sivakorn, George Argyros, Kexin Pei, Angelos D. Keromytis 等S&P 2017 · 被引用 88 次
- SweynTooth: Unleashing Mayhem over Bluetooth Low EnergyMatheus E. Garbelini, Chundong Wang, Sudipta Chattopadhyay, Sumei Sun 等USENIX ATC 2020 · 被引用 83 次
- SFADiff: Automated Evasion Attacks and Fingerprinting Using Black-box Differential Automata LearningGeorge Argyros, Ioannis Stais, Suman Jana, Angelos D. Keromytis 等CCS 2016 · 被引用 65 次
相关 Paper
- Automata-Based Automated Detection of State Machine Bugs in Protocol ImplementationsPaul Fiterau-Brostean, Bengt Jonsson, Konstantinos Sagonas, Fredrik TåquistNDSS 2023
- Terrapin Attack: Breaking SSH Channel Integrity By Sequence Number ManipulationFabian Bäumer, Marcus Brinkmann, Jörg SchwenkUSENIX Security 2024 · 被引用 15 次
- Post-Quantum Cryptographic Analysis of SSHBenjamin Bencina, Benjamin Dowling, Varun Maram, Keita XagawaS&P 2025
- Where The Wild Things Are: Brute-Force SSH Attacks In The Wild And How To Stop ThemSachin Kumar Singh, Shreeman Gautam, Cameron Cartier, Sameer Patil 等NSDI 2024 · 被引用 15 次
- A Surfeit of SSH Cipher SuitesMartin R. Albrecht, Jean Paul Degabriele, Torben Brandt Hansen, Kenneth G. PatersonCCS 2016 · 被引用 36 次
