Skip to main content
QUICK REVIEW

[论文解读] The Hijackers Guide To The Galaxy: Off-Path Taking Over Internet Resources

Tianxiang Dai, Philipp Jeitner|arXiv (Cornell University)|May 11, 2022
Network Security and Intrusion Detection参考文献 22被引用 7
一句话总结

本文表明,非路径(off-path)网络攻击者可通过DNS缓存投毒,劫持互联网资源账户——如IP地址、域名、证书和云服务账户——将密码重置链接重定向至其控制的服务器。该攻击可实现对关键互联网基础设施的隐蔽、长期控制,其中68%的IPv4地址空间和31%的顶级域名易受此类劫持影响。

ABSTRACT

Internet resources form the basic fabric of the digital society. They provide the fundamental platform for digital services and assets, e.g., for critical infrastructures, financial services, government. Whoever controls that fabric effectively controls the digital society. In this work we demonstrate that the current practices of Internet resources management, of IP addresses, domains, certificates and virtual platforms are insecure. Over long periods of time adversaries can maintain control over Internet resources which they do not own and perform stealthy manipulations, leading to devastating attacks. We show that network adversaries can take over and manipulate at least 68% of the assigned IPv4 address space as well as 31% of the top Alexa domains. We demonstrate such attacks by hijacking the accounts associated with the digital resources. For hijacking the accounts we launch off-path DNS cache poisoning attacks, to redirect the password recovery link to the adversarial hosts. We then demonstrate that the adversaries can manipulate the resources associated with these accounts. We find all the tested providers vulnerable to our attacks. We recommend mitigations for blocking the attacks that we present in this work. Nevertheless, the countermeasures cannot solve the fundamental problem - the management of the Internet resources should be revised to ensure that applying transactions cannot be done so easily and stealthily as is currently possible.

研究动机与目标

  • 调查互联网资源管理系统的安全性,包括RIR、域名注册商、CA和IaaS提供商。
  • 评估非路径攻击者在无直接网络访问权限的情况下劫持客户账户的可行性。
  • 展示被劫持账户如何被用于操纵关键互联网基础设施,包括BGP路由和证书签发。
  • 识别主要提供商在账户恢复和访问控制机制方面存在的系统性弱点。
  • 提出实用的缓解措施,并倡导对互联网资源管理进行根本性重构,以防止隐蔽、长期的攻击。

提出的方法

  • 实施非路径DNS缓存投毒攻击,将密码重置邮件重定向至攻击者控制的主机。
  • 利用弱或缺失的CAPTCHA机制,自动化重复的密码重置请求。
  • 通过被劫持的电子邮件传递,获得对RIR、注册商、CA和IaaS平台受害账户的完全访问权限。
  • 利用被劫持账户操纵IRR记录,通过受信任的上游提供商实现隐蔽的BGP前缀劫持。
  • 在多个提供商的真实且隔离的受害账户上开展受控、合乎伦理的渗透测试,以验证攻击的可利用性。
  • 评估DNSSEC的部署情况与有效性,识别广泛存在的配置错误和弱加密实践。

实验结果

研究问题

  • RQ1非路径攻击者仅通过DNS缓存投毒,能在多大程度上劫持互联网资源账户?
  • RQ2当前账户恢复机制在主要提供商中防止此类攻击的有效性如何?
  • RQ3账户被攻破对更广泛的互联网基础设施有何影响,特别是对BGP前缀劫持的促进作用?
  • RQ4互联网资源注册机构中DNSSEC部署的配置错误和密钥强度问题有多普遍?
  • RQ5哪些技术和政策层面的缓解措施能有效应对此类隐蔽、长期的账户劫持攻击?

主要发现

  • 68%的已分配IPv4地址空间和31%的顶级Alexa域名易受非路径DNS缓存投毒导致的账户劫持影响。
  • 所有测试的提供商——包括RIR、域名注册商、CA和IaaS平台——均易受所提出的账户劫持技术影响。
  • 被劫持的RIR账户可使攻击者操纵IRR记录,从而通过可信上游提供商实现高效且隐蔽的BGP前缀劫持。
  • 在AFRINIC下辖的LIR域名中仅3.78%正确使用DNSSEC签名,注册商下辖的为5.88%,且许多使用弱密钥或易受攻击的哈希函数。
  • 许多提供商缺乏基本防护措施,如CAPTCHA或电子邮件通知机制,这些机制本可用于检测或阻止自动化攻击。
  • 即使部署了DNSSEC,人为错误和配置错误仍使系统处于风险之中,凸显了需要额外技术防护措施的必要性。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。