A Fragmentation Considered Vulnerable

نویسندگان

  • Yossi Gilad
  • Amir Herzberg
چکیده

We show that fragmented IPv4 and IPv6 traffic is vulnerable to effective interception and denial-of-service (DoS) attacks by an off-path attacker. Specifically, we demonstrate a weak attacker intercepting more than 80% of the data between peers and causing over 94% loss rate. We show that our attacks are practical through experimental validation on popular industrial and opensource products, with realistic network setups that involve NAT or tunneling and include concurrent legitimate traffic as well as packet losses. The interception attack requires a zombie agent behind the same NAT or tunnel-gateway as the victim destination; the DoS attack only requires a puppet agent, i.e., a sandboxed applet or script running in web-browser context. The complexity of our attacks depends on the predictability of the IP Identification (ID) field which is typically implemented as one or multiple counters, as allowed and recommended by the IP specifications. The attacks are much simpler and more efficient for implementations, such as Windows, which use one ID counter for all destinations. Therefore, much of our focus is on presenting effective attacks for implementations, such as Linux, which use per-destination ID counters. We present practical defenses for the attacks presented in this paper, the defenses can be deployed on network firewalls without changes to hosts or operating system kernel.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

A Review of our Current Knowledge of Clouded Leopards (Neofelis nebulosa)

The global population of clouded leopards (Neofelis nebulosa) is considered vulnerable worldwide [1], and were considered to be less abundant globally the 2016 assessment by the IUCN than the previous assessment in 2007 [1]. Clouded leopards currently range from the southeastern Himalayas across southeastern Asia, extending through southern China and into peninsular Malaysia [2-6] (Figure 1). T...

متن کامل

High Dispersal in a Frog Species Suggest that it is Vulnerable to Habitat Fragmentation

Global losses of amphibian populations are a major conservation concern and have generated substantial debate over their causes. Habitat fragmentation is considered one important cause of amphibian decline. However, if fragmentation is to be invoked as a mechanism of amphibian decline, it must first be established that dispersal is prevalent among contiguous amphibian populations using formal m...

متن کامل

Fragmentation Considered Vulnerable: Blindly Intercepting and Discarding Fragments

The key to their attack is to determine the IP ID. This is trivial with Windows, which uses a monotonically increasing IP ID. Linux uses a per-destination IP ID, which makes determining the IP ID more difficult. In their attacks, they make use of a sandboxed script, PuZo, on the victim’s network, to watch for fragments that do not show up. The missing fragments must have had a valid IP ID, and ...

متن کامل

High dispersal in a frog species suggests that it is vulnerable to habitat fragmentation.

Global losses of amphibian populations are a major conservation concern and their causes have generated substantial debate. Habitat fragmentation is considered one important cause of amphibian decline. However, if fragmentation is to be invoked as a mechanism of amphibian decline, it must first be established that dispersal is prevalent among contiguous amphibian populations using formal moveme...

متن کامل

Theory meets reality: How habitat fragmentation research has transcended island biogeographic theory

Island biogeography theory (IBT) provides a basic conceptual model for understanding habitat fragmentation. Empirical studies of fragmented landscapes often reveal strong effects of fragment area and isolation on species richness, although other predictions of the theory, such as accelerated species turnover in fragments, have been tested less frequently. As predicted by IBT, biota in fragments...

متن کامل

Modelling the catalyst fragmentation pattern in relation to molecular properties and particle overheating in olefin polymerization

A two-dimensional single particle finite element model was used to examine the effects of particle fragmental pattern on the average molecular weights, polymerization rate and particle overheating in heterogeneous Ziegler-Natta olefin polymerization. A two-site catalyst kinetic mechanism was employed together with a dynamic two-dimensional molecular species in diffusion-reaction equation. The i...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2012