论文标题

Stalloris:RPKI降级攻击

Stalloris: RPKI Downgrade Attack

论文作者

Hlavacek, Tomas, Jeitner, Philipp, Mirdita, Donika, Shulman, Haya, Waidner, Michael

论文摘要

我们演示了针对RPKI的第一次降级攻击。 RPKI中允许我们攻击的关键设计属性是连接和安全之间的权衡:当网络无法从出版物中检索RPKI信息时,它们在不验证RPKI的情况下在BGP中做出路由决策。我们利用这一权衡来开发攻击,以防止从公共存储库中检索RPKI对象,从而禁用RPKI验证并将受RPKI-Protew的网络暴露于前缀劫持攻击。 我们通过实验证明,至少有47%的公共存储库容易与我们的攻击的特定版本,这是限制速率的降级降级攻击。我们还表明,当前所有依赖政党实施的RPKI都容易受到恶意出版物的攻击。这意味着IPv4地址空间的20.4%。 我们提供了防止降级攻击的建议。但是,解决基本问题并不直接:如果依赖方更喜欢安全性而不是连接性,而在无法检索ROA时坚持RPKI验证,那么受害者可能会与许多网络脱节,而不仅仅是对手希望抢劫的网络。我们的工作表明,出版点是Internet连接和安全性的关键基础架构。因此,我们的主要建议是,出版物应托管在可确保高度连接的稳健平台上。

We demonstrate the first downgrade attacks against RPKI. The key design property in RPKI that allows our attacks is the tradeoff between connectivity and security: when networks cannot retrieve RPKI information from publication points, they make routing decisions in BGP without validating RPKI. We exploit this tradeoff to develop attacks that prevent the retrieval of the RPKI objects from the public repositories, thereby disabling RPKI validation and exposing the RPKI-protected networks to prefix hijack attacks. We demonstrate experimentally that at least 47% of the public repositories are vulnerable against a specific version of our attacks, a rate-limiting off-path downgrade attack. We also show that all the current RPKI relying party implementations are vulnerable to attacks by a malicious publication point. This translates to 20.4% of the IPv4 address space. We provide recommendations for preventing our downgrade attacks. However, resolving the fundamental problem is not straightforward: if the relying parties prefer security over connectivity and insist on RPKI validation when ROAs cannot be retrieved, the victim AS may become disconnected from many more networks than just the one that the adversary wishes to hijack. Our work shows that the publication points are a critical infrastructure for Internet connectivity and security. Our main recommendation is therefore that the publication points should be hosted on robust platforms guaranteeing a high degree of connectivity.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源