Exploring the Unknown DTLS Universe: Analysis of the DTLS Server Ecosystem on the Internet
Nurullah Erinola, Marcel Maehren, Robert Merget, Juraj Somorovsky, Jörg Schwenk
摘要
DTLS aims to bring the same security guarantees as TLS to UDP. It is used for latency-sensitive applications such as VPN, VoIP, video conferencing, and online gaming that can suffer from the overhead of a reliable transport protocol like TCP. While researchers and developers invested significant effort in improving the security of TLS, DTLS implementations have not received the same scrutiny despite their importance and similarity. It is thus an open question whether vulnerabilities discovered in TLS have been fixed in DTLS and whether DTLS-specific features open possibilities for new attacks. To fill this gap, we extended the open-source tool TLS-Scanner with support for DTLS and implemented additional tests for DTLS-exclusive features. We evaluated twelve opensource DTLS server implementations and uncovered eleven security vulnerabilities, including a padding oracle vulnerability in PionDTLS and DoS amplification vulnerabilities in wolfSSL, Scandium, and JSSE. We then proceeded to scan publicly available servers. We discovered and analyzed more than 500,000 DTLS servers across eight ports providing detailed insights into the publicly accessible DTLS server landscape. Beyond cryptographic vulnerabilities and compatibility issues, our analysis showed that 4.4% of the evaluated servers could be used for DoS amplification attacks due to insufficient care when handling anti-DoS cookies.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- AirSnitch: Demystifying and Breaking Client Isolation in Wi-Fi NetworksXin'an Zhou, Juefei Pu, Zhutian Liu, Zhiyun Qian 等NDSS 2026 · 被引用 1 次
- Analyzing the WebRTC Ecosystem and Breaking Authentication in DTLS-SRTPMartin Bach, Vukašin Karadžić, Lukas Knittel, Robert Merget 等USENIX Security 2026
它引用的顶会 Paper14
- DROWN: Breaking TLS Using SSLv2Nimrod Aviram, Sebastian Schinzel, Juraj Somorovsky, Nadia Heninger 等USENIX Security 2016 · 被引用 192 次
- On the Practical (In-)Security of 64-bit Block Ciphers: Collision Attacks on HTTP over TLS and OpenVPNKarthikeyan Bhargavan, Gaëtan LeurentCCS 2016 · 被引用 180 次
- Systematic Fuzzing and Testing of TLS LibrariesJuraj SomorovskyCCS 2016 · 被引用 136 次
- TLS in the Wild: An Internet-wide Analysis of TLS-based Protocols for Electronic CommunicationRalph Holz, Johanna Amann, Olivier Mehani, Mohamed Ali Kâafar 等NDSS 2016 · 被引用 117 次
- The use of TLS in Censorship CircumventionSergey Frolov, Eric WustrowNDSS 2019 · 被引用 97 次
相关 Paper
- Analysis of DTLS Implementations Using Protocol State FuzzingPaul Fiterau-Brostean, Bengt Jonsson, Robert Merget, Joeri de Ruiter 等USENIX Security 2020
- Scalable Scanning and Automatic Classification of TLS Padding Oracle VulnerabilitiesRobert Merget, Juraj Somorovsky, Nimrod Aviram, Craig Young 等USENIX Security 2019 · 被引用 27 次
- LanDscAPe: Exploring LDAP weaknesses and data leaks at Internet scaleJonas Kaspereit, Gurur Öndarö, Gustavo Luvizotto Cesar, Simon Ebbers 等USENIX Security 2024 · 被引用 5 次
- AmpFuzz: Fuzzing for Amplification DDoS VulnerabilitiesJohannes Krupp, Ilya Grishchenko, Christian RossowUSENIX Security 2022
- TLS-Anvil: Adapting Combinatorial Testing for TLS LibrariesMarcel Maehren, Philipp Nieting, Sven Hebrok, Robert Merget 等USENIX Security 2022
