ONIS: Inferring TCP/IP-based Trust Relationships Completely Off-Path

被引:0
作者
Zhang, Xu [1 ]
Knockel, Jeffrey [1 ]
Crandall, Jedidiah R. [1 ]
机构
[1] Univ New Mexico, Dept Comp Sci, Albuquerque, NM 87131 USA
来源
IEEE CONFERENCE ON COMPUTER COMMUNICATIONS (IEEE INFOCOM 2018) | 2018年
基金
美国国家科学基金会;
关键词
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
We present ONIS, a new scanning technique that can perform network measurements such as: inferring TCP/IP-based trust relationships off-path, stealthily port scanning a target without using the scanner's IP address, detecting off-path packet drops between two international hosts. These tasks typically rely on a core technique called the idle scan, which is a special kind of port scan that appears to come from a third machine called a zombie. The scanner learns the target's status from the zombie by using its TCP/IP side channels. Unfortunately, the idle scan assumes that the zombie has IP identifiers (IPIDs) which exhibit the now-discouraged behavior of being globally incrementing. The use of this kind of IPID counter is becoming increasingly rare in practice. Our technique, unlike the idle scan, is based on a much more advanced IPID generation scheme, that of the prevalent Linux kernel. Although Linux's IPID generation scheme is specifically intended to reduce information flow, we show that using Linux machines as zombies in an indirect scan is still possible. ONIS has 87% accuracy, which is comparable to nmap's implementation of the idle scan at 86%. ONIS's much broader choice of zombies will enable it to be a widely used technique which can fulfill various network measurement tasks.
引用
收藏
页码:2078 / 2086
页数:9
相关论文
共 38 条
  • [1] [Anonymous], 1998, NEW TEP SCAN METH PO
  • [2] Bellovin SM, 2002, IMW 2002: PROCEEDINGS OF THE SECOND INTERNET MEASUREMENT WORKSHOP, P267, DOI 10.1145/637201.637243
  • [3] Cannady J., 1998, P 21 NATL INFORM SYS, P368
  • [4] Cao Y., 25 USENIX SEC S USEN, P209
  • [5] Chen WF, 2005, LECT NOTES COMPUT SC, V3431, P108, DOI 10.1007/978-3-540-31966-5_9
  • [6] Dumazet E., 2014, ip: make ip identifiers less predictable
  • [7] Dumazet E., 2014, inetpeer: get rid of ip id count
  • [8] Ensafi Roya, 2014, Passive and Active Measurement. 15th International Conference, PAM 2014. Proceedings: LNCS 8362, P109, DOI 10.1007/978-3-319-04918-2_11
  • [9] Ensafi R., DETECTING INT PACKET
  • [10] Ensafi R., 2013, DETECTING INTENTIONA