Skip to main content
QUICK REVIEW

[论文解读] Hijacking Bitcoin: Large-scale Network Attacks on Cryptocurrencies.

Maria Apostolaki, Aviv Zohar|arXiv (Cornell University)|May 24, 2016
Blockchain Technology Applications and Security参考文献 19被引用 21
一句话总结

本文表明,通过使用少于900个前缀的BGP前缀劫持,大规模的网络层攻击(如隔离50%的挖矿算力或延迟区块传播)在比特币网络中是可行的。该攻击利用了比特币的路由与挖矿集中化,以及其通信协议中未加密、未认证的消息传输,从而导致严重的中断和挖矿算力浪费与双重支付风险,造成显著的经济损失。

ABSTRACT

Bitcoin is without a doubt the most successful cryptocurrency in circulation today, making it an extremely valuable target for attackers. Indeed, many studies have highlighted ways to compromise one or several Bitcoin nodes. In this paper, we take a different perspective and study the effect of large-scale network-level attacks such as the ones that may be launched by Autonomous Systems (ASes). We show that attacks that are commonly believed to be hard, such as isolating 50% of the mining power, are actually within the reach of anyone with access to a BGP-enabled network and hijacking less than 900 prefixes. Once on path, AS-level adversaries can then partition the Bitcoin network or delay block propagation significantly. The key factors that enable these attacks are the extreme centralization of Bitcoin, both from a routing and a mining perspective, along with the fact that Bitcoin messages are sent unencrypted, without integrity guarantees. We demonstrate the feasibility of large-scale attacks in practice against the deployed Bitcoin software and quantify their disruptive network-wide impact. The potential damage to Bitcoin is severe. By isolating a part of the network or delaying the propagation of blocks, network-level attackers can cause a significant amount of mining power to be wasted, leading to revenue losses and enabling a wide range of attacks such as double spending. We provide several suggestions on approaches to mitigate such attacks employing both short-term and long-term measures.

研究动机与目标

  • 调查针对比特币网络基础设施而非单个节点的大规模网络层攻击的可行性。
  • 分析拥有BGP访问权限的自治系统(AS)如何通过前缀劫持破坏比特币的点对点网络。
  • 量化此类攻击对区块传播延迟和网络分区的影响。
  • 识别脆弱性的根本原因,包括路由与挖矿集中化,以及比特币通信协议中缺乏消息完整性。
  • 提出短期与长期缓解策略,以增强比特币对基础设施级别威胁的弹性。

提出的方法

  • 研究人员对比特币的网络拓扑和路由基础设施进行了大规模测量研究,以识别集中化节点。
  • 他们使用真实世界的AS配置模拟了BGP前缀劫持攻击,以评估目标挖矿池的可达性与隔离潜力。
  • 该研究使用实时比特币网络数据,在各种劫持场景下测量了区块传播延迟和网络分区效应。
  • 研究人员评估了未加密、未认证的消息传输对网络抵御中间人攻击和重放攻击能力的影响。
  • 他们分析了比特币协议栈,以识别可通过网络层操纵引发大规模破坏的协议级弱点。
  • 该团队提出了并评估了缓解技术,包括BGP安全加固、消息认证和路由策略加固,以减少攻击面。

实验结果

研究问题

  • RQ1拥有BGP访问权限的AS级对手,通过使用有限数量的前缀,能在多大程度上隔离比特币挖矿算力的显著部分?
  • RQ2网络层劫持在多大程度上影响比特币网络中的区块传播延迟和共识完整性?
  • RQ3比特币路由与挖矿基础设施的集中化在多大程度上助长了大规模网络攻击?
  • RQ4缺乏消息加密和完整性校验在多大程度上加剧了网络层被攻破的风险?
  • RQ5在生产环境中,可以实施哪些实际的缓解策略,以降低此类攻击的可行性与影响?

主要发现

  • 拥有BGP访问权限的攻击者可通过劫持少于900个前缀,将高达50%的比特币挖矿算力隔离。
  • 模拟中观察到高达数秒的区块传播延迟,显著增加了区块失效和孤块的风险。
  • 网络分区攻击导致可测量的挖矿收入损失,原因在于计算资源被浪费在冲突的区块链上。
  • 比特币路由与挖矿基础设施的极端集中化造成了可被网络层操纵利用的单点故障。
  • 比特币点对点协议中缺乏端到端的消息认证与加密,使得大规模中间人攻击和重放攻击成为可能。
  • 本研究证实,此类攻击并非理论假设,而是可利用现有网络基础设施与工具实际实施的。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。