Matches in SemOpenAlex for { <https://semopenalex.org/work/W3204548492> ?p ?o ?g. }
- W3204548492 endingPage "422" @default.
- W3204548492 startingPage "409" @default.
- W3204548492 abstract "In this paper, we uncover a new off-path TCP hijacking attack that can be used to terminate victim TCP connections or inject forged data into victim TCP connections by manipulating the new mixed IPID assignment method, which is widely used in Linux kernel version 4.18 and beyond. Our attack has three steps. First, an off-path attacker can downgrade the IPID assignment for TCP packets from the more secure per-socket-based policy to the less secure hash-based policy, thus building a shared IPID counter that forms a side channel in the victim. Second, the attacker detects the presence of TCP connections by observing the side channel of the shared IPID counter. Third, the attacker infers sequence and acknowledgment numbers of the detected connection by observing the side channel. Consequently, the attacker can completely hijack the connection, e.g., resetting the connection or poisoning the data stream. We evaluate the impacts of our attack in the real world, and we uncover that more than 20% of Alexa top 100k websites are vulnerable to our attack. Our case studies of SSH DoS, manipulating web traffic, and poisoning BGP routing tables show its threat on a wide range of applications. Moreover, we demonstrate that our attack can be further extended to exploit IPv4/IPv6 dual-stack networks on increasing the hash collisions and enlarging vulnerable populations. Finally, we analyze the root cause and develop a new IPID assignment method to defeat this attack. We prototype our defense in Linux 4.18 and confirm its effectiveness in the real world." @default.
- W3204548492 created "2021-10-11" @default.
- W3204548492 creator A5026728546 @default.
- W3204548492 creator A5032588791 @default.
- W3204548492 creator A5035868158 @default.
- W3204548492 creator A5050493033 @default.
- W3204548492 creator A5072990224 @default.
- W3204548492 date "2022-02-01" @default.
- W3204548492 modified "2023-10-18" @default.
- W3204548492 title "Off-Path TCP Hijacking Attacks via the Side Channel of Downgraded IPID" @default.
- W3204548492 cites W1593925121 @default.
- W3204548492 cites W1677315679 @default.
- W3204548492 cites W1692207811 @default.
- W3204548492 cites W1714781699 @default.
- W3204548492 cites W1888844539 @default.
- W3204548492 cites W2041188073 @default.
- W3204548492 cites W2070670160 @default.
- W3204548492 cites W2081464537 @default.
- W3204548492 cites W2117654928 @default.
- W3204548492 cites W2133467782 @default.
- W3204548492 cites W2147491888 @default.
- W3204548492 cites W2155750235 @default.
- W3204548492 cites W2165976789 @default.
- W3204548492 cites W2287831134 @default.
- W3204548492 cites W2288359499 @default.
- W3204548492 cites W2301803821 @default.
- W3204548492 cites W25350463 @default.
- W3204548492 cites W2706122055 @default.
- W3204548492 cites W2787167933 @default.
- W3204548492 cites W2790127834 @default.
- W3204548492 cites W2791547242 @default.
- W3204548492 cites W2794568842 @default.
- W3204548492 cites W2914876907 @default.
- W3204548492 cites W2925381967 @default.
- W3204548492 cites W2962940036 @default.
- W3204548492 cites W2965279841 @default.
- W3204548492 cites W2985610488 @default.
- W3204548492 cites W2988979713 @default.
- W3204548492 cites W3007224029 @default.
- W3204548492 cites W3099114729 @default.
- W3204548492 cites W4213107800 @default.
- W3204548492 cites W4230038347 @default.
- W3204548492 cites W4235381699 @default.
- W3204548492 cites W4243835522 @default.
- W3204548492 cites W4251260016 @default.
- W3204548492 cites W4292117754 @default.
- W3204548492 cites W4300296722 @default.
- W3204548492 cites W1981586018 @default.
- W3204548492 doi "https://doi.org/10.1109/tnet.2021.3115517" @default.
- W3204548492 hasPublicationYear "2022" @default.
- W3204548492 type Work @default.
- W3204548492 sameAs 3204548492 @default.
- W3204548492 citedByCount "3" @default.
- W3204548492 countsByYear W32045484922023 @default.
- W3204548492 crossrefType "journal-article" @default.
- W3204548492 hasAuthorship W3204548492A5026728546 @default.
- W3204548492 hasAuthorship W3204548492A5032588791 @default.
- W3204548492 hasAuthorship W3204548492A5035868158 @default.
- W3204548492 hasAuthorship W3204548492A5050493033 @default.
- W3204548492 hasAuthorship W3204548492A5072990224 @default.
- W3204548492 hasConcept C104954878 @default.
- W3204548492 hasConcept C110875604 @default.
- W3204548492 hasConcept C111919701 @default.
- W3204548492 hasConcept C158379750 @default.
- W3204548492 hasConcept C165696696 @default.
- W3204548492 hasConcept C178489894 @default.
- W3204548492 hasConcept C31258907 @default.
- W3204548492 hasConcept C35546906 @default.
- W3204548492 hasConcept C38652104 @default.
- W3204548492 hasConcept C41008148 @default.
- W3204548492 hasConcept C49289754 @default.
- W3204548492 hasConcept C553261973 @default.
- W3204548492 hasConcept C84555802 @default.
- W3204548492 hasConcept C89305328 @default.
- W3204548492 hasConcept C99138194 @default.
- W3204548492 hasConceptScore W3204548492C104954878 @default.
- W3204548492 hasConceptScore W3204548492C110875604 @default.
- W3204548492 hasConceptScore W3204548492C111919701 @default.
- W3204548492 hasConceptScore W3204548492C158379750 @default.
- W3204548492 hasConceptScore W3204548492C165696696 @default.
- W3204548492 hasConceptScore W3204548492C178489894 @default.
- W3204548492 hasConceptScore W3204548492C31258907 @default.
- W3204548492 hasConceptScore W3204548492C35546906 @default.
- W3204548492 hasConceptScore W3204548492C38652104 @default.
- W3204548492 hasConceptScore W3204548492C41008148 @default.
- W3204548492 hasConceptScore W3204548492C49289754 @default.
- W3204548492 hasConceptScore W3204548492C553261973 @default.
- W3204548492 hasConceptScore W3204548492C84555802 @default.
- W3204548492 hasConceptScore W3204548492C89305328 @default.
- W3204548492 hasConceptScore W3204548492C99138194 @default.
- W3204548492 hasFunder F4320321001 @default.
- W3204548492 hasFunder F4320329777 @default.
- W3204548492 hasFunder F4320334953 @default.
- W3204548492 hasFunder F4320335777 @default.
- W3204548492 hasFunder F4320337345 @default.
- W3204548492 hasFunder F4320338281 @default.
- W3204548492 hasIssue "1" @default.
- W3204548492 hasLocation W32045484921 @default.