0% found this document useful (0 votes)
3 views39 pages

Network Attacks

The document discusses various network attacks and security goals, emphasizing confidentiality, integrity, and availability. It outlines different attacker capabilities and types of threats across various layers, including physical, link, network, and transport layers. Additionally, it highlights specific attack methods such as eavesdropping, packet injection, and DHCP spoofing, along with tools used for network traffic analysis.

Uploaded by

hihijibuhihi
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
3 views39 pages

Network Attacks

The document discusses various network attacks and security goals, emphasizing confidentiality, integrity, and availability. It outlines different attacker capabilities and types of threats across various layers, including physical, link, network, and transport layers. Additionally, it highlights specific attack methods such as eavesdropping, packet injection, and DHCP spoofing, along with tools used for network traffic analysis.

Uploaded by

hihijibuhihi
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Unit 5: Security

Network Attacks
Instructor: Malik Alfilali
UCT

Some material from Deian Stefan, Zakir Durumeric, David Wagner


Threat modeling for network attacks
Threat modeling for network attacks

Basic security goals:


• Confidentiality: No one should be able to read our
data/communications unless we want them to.

• Integrity: No one can manipulate our


data/communications unless we want them to.

• Availability: We can access our data/communication


capabilities when we want to.
Threat modeling for network attacks
Threat modeling for network attacks

Attacker capabilities:
• Physical access: Attacker has physical access to the
network infrastructure.

• In path/Man in the middle: Attacker can see, add, and


block packets.

• On path/Man on the side: Attacker can see and add


packets, but cannot block packets.

• Passive: Attacker can see victim’s network traffic, but


cannot add or modify packets.

• Off path: Attacker cannot see network traffic of the


victim.
Different attacks at different layers
Different attacks at different layers

Application • DNS, HTTP, HTTPS

Transport • TCP, UDP

Network • IP, BGP

Data Link • Ethernet, WiFi, ARP

Physical • Physical wires, photons, RF modulation


Physical/link layer threats
Physical/link layer threats

Eavesdropping: Violates con1dentiality.

Who can see the packets you send?


• Network (routers, switches, access points) see all traffic
passing by.
Physical/link layer threats
Physical/link layer threats

Eavesdropping: Violates con1dentiality.

Who can see the packets you send?


• Network (routers, switches, access points) see all traffic
passing by.
• Unprotected WiFi network:
• WPA2 Personal (PSK):
• Non-switched Ethernet:
• Switched Ethernet: maybe everyone on the same
network
Network eavesdropping
Network eavesdropping
Tools like tcpdump and Wireshark let you capture local network tra ffic
$ sudo tcpdump - v -n - i eno1
tcpdump: l is t e ni ng on eno1, l ink - t y pe EN10MB ( E th er ne t ) , capture s ize 262144 bytes
17: 29:41.757880 IP ( t os 0x10, t t l 64 , id 38565, of f se t 0 , f l a g s [ DF ], proto TCP ( 6 ) , length 176)14)
[Link].4258 > [Link].62681: Flags [ P . ] , cksum 0x3bc5 ( in cor re ct -> 0x2e82), seq 1687079
17: 29:41.770734 IP ( t os 0x0, t t l 50 , id 0 , of f se t 0 , f l a g s [ DF ], proto TCP ( 6 ) , length 52)
[Link].62681 > [Link].4258: Flags [ . ] , cksum 0x8e71 ( c or re c t ) , ack 124, win 11736, opti
17: 29:41.789239 ARP, Ethernet ( l e n 6 ) , IPv 4 ( l e n 4 ) , Request who-has [Link] t e l l [Link], l e
17: 29:41.936864 IP ( t os 0x0, t t l 1 , id 20121, of f se t 0 , f l a g s [ none ] , proto UDP ( 1 7) , length 202)
[Link].65021 > [Link].1900: U DP, l ength 174
17: 29:42.036268 IP6 (hlim 1 , next-header UDP (17) payload l e ng t h: 83) fe 80 : : 225 : b3f f: fe fa : a1 3d .54 6 > ff02
17: 29:42.390349 IP ( t os 0x0, t t l 64 , id 35459, of f se t 0 , f l a g s [ DF ], proto UDP ( 1 7) , length 51)
[Link].40288 > [Link].443: U DP, l ength 23
17: 29:42.419390 IP ( t os 0x0, t t l 57 , id 0 , of f se t 0 , f l a g s [ DF ], proto UDP ( 1 7) , length 48)
[Link].443 > [Link].40288: U DP, l ength 20
17: 29:42.443102 ARP, Ethernet ( l e n 6 ) , IPv 4 ( l e n 4 ) , Request who-has [Link] t e l l [Link], len
17:29: 42.541827 ST P 802.1 w, R apid S TP, Fl ag s [ Le a rn, Forwa rd], brid g e- id 81b0.00 :a 3:d 1:25 :06: 00.8 01a, len
message-age 2 .0 0s , max-age 20 .0 0s, he l l o- t ime 2 .0 0s , forwarding-delay 15.00s
roo t- id 21b 0.3c :0 8: f6: 21: a 8: 40, root-pa t hcost 200 1, po rt- rol e Designated
17: 29:43.752250 IP ( t os 0x0, t t l 64 , id 61970, of f se t 0 , f l a g s [ DF ], proto TCP ( 6 ) , length 109)
[Link].55866 > [Link].443: Flags [ P . ] , cksum 0xbd14 ( in cor re ct -> 0x cf bd) , seq 3280138
17: 29:43.788285 IP ( t os 0x0, t t l 38 , id 43082, of f se t 0 , f l a g s [ DF ], proto TCP ( 6 ) , length 109)
[Link].443 > [Link].55866: Flags [ P . ] , cksum 0x65eb ( c or re c t ) , seq 1: 5 8, ack 57 , wi n 8
17: 29:43.788311 IP ( t os 0x0, t t l 64 , id 61971, of f se t 0 , f l a g s [ DF ], proto TCP ( 6 ) , length 52)
[Link].55866 > [Link].443: Flags [ . ] , cksum 0xbcdb ( in cor re ct -> 0xab20), ack 58 , win
17: 29:43.905367 IP ( t os 0x0, t t l 128, id 19913, of f se t 0 , f l a g s [ none ] , proto UDP ( 1 7) , length 414)
[Link].17500 > [Link].17500: U DP, l ength 386
17: 29:43.907037 IP ( t os 0x0, t t l 128, id 59034, of f se t 0 , f l a g s [ none ] , proto UDP ( 1 7) , length 414)
[Link].17500 > [Link].17500: UDP, l ength 386
17: 29:43.907052 IP ( t os 0x0, t t l 128, id 19914, of f se t 0 , f l a g s [ none ] , proto UDP ( 1 7) , length 414)
[Link].17500 > [Link].17500: U DP, l ength 386
17: 29:43.907057 IP ( t os 0x0, t t l 128, id 19915, of f se t 0 , f l a g s [ none ] , proto UDP ( 1 7) , length 414)
[Link].17500 > [Link].17500: U DP, l ength 386
17: 29:43.907060 IP ( t os 0x0, t t l 128, id 19916, of f se t 0 , f l a g s [ none ] , proto UDP ( 1 7) , length 414)
Advanced threats: Physical cables can be tapped
ti ��� ·1•...:1
TOPSECRET//S1//0RCON//NOF.. Google � patalkw, You,...
ti��
� Hotmall'
G� J I·1 •••• Y AE 0O. r � ·1•...:1 ·A·-O-L-S-,,mau,I�:w

(fS/tsvJNF) FAA702 Operations


Two Types of Collection

Upstream
• Collection of communications on fiber cables
• frastructure as data flows past.

Yo
Shou
UseB

• Collection directly from the servers of these U.S.


Service Providers: Microsoft, Yahoo, Google
Facebook, PalTalk, AOL, Skype, YouTube
A le.
TOPSECRET//S1//0RCON//NOFORi'I
Optic Nerve
Optic Nerve
“Optic Nerve was based on collecting information from
GCHQ ’s huge network of internet cable taps, which was then
processed and fed into systems provided by the NSA.
Webcam information was fed into NSA ’s XKeyscore search
tool, and NSA research was used to build the tool which
identi1ed Yahoo’s webcam traffic.”

– The Guardian 2/27/14


Optic Nerve
Optic Nerve
“Optic Nerve was based on collecting information from
GCHQ ’s huge network of internet cable taps, which was then
processed and fed into systems provided by the NSA.
Webcam information was fed into NSA ’s XKeyscore search
tool, and NSA research was used to build the tool which
identi1ed Yahoo’s webcam traffic.”

– The Guardian 2/27/14


Advanced threats: Physical cables can be tapped
Advanced threats: Physical cables can be tapped

Trevor Paglen, NSA-Tapped Undersea Cab les, North Paci1c Ocean, 2016
Physical/link layer threats
Physical/link layer threats

Injection: Violates integrity.

• Ethernet packets are unauthenticated: attacker who can


inject traffic can create a frame with any addresses they
like.
Packet injection: ARP spoofing
Packet injection: ARP spoofing

• Recall: ARP used to map IP addresses to MAC addresses


on local network
$ sudo tcpdump - v -n - i eno1
tcpdump: l is t e ni ng on eno1, l ink - t y pe EN10MB ( E th er ne t ) , capture s ize 262144 bytes
17: 29:47.455929 ARP, Ethernet ( l e n 6 ) , IPv 4 ( l e n 4 ) , Request who-has [Link]
t e l l [Link], l ength 46

• ARP requests broadcast to local subnetwork

• Anyone can send an ARP response

• Attacker on local network can impersonate any other


host.
Physical/link layer threats
Physical/link layer threats

Jamming: Violates availability.

• Physical signals can be overwhelmed or disrupted.


• Radio transmission depends on power and distance.
Radio jamming: P25 law enforcement radios
Radio jamming: P25 law enforcement radios
Radio jamming: P25 law enforcement radios

Why (Special Agent) Johnny (Still) Can ’t Encrypt: A Security Analysis of the APCO Proje ct 25 Two-Way Radio
System Clark et al. 2011
Network layer threats
Network layer threats

Spoofing: Set arbitrary source address.

• IP packets offer no authentication.


• Source address in IP set by sender.
• Off-path attacker who spoofs a source address may not
be able to see response sent to that address.
(Sometimtimes that’s okay.)
Example: DH CP response spoo 1 ng

• Recall: DHCP used to con 1gure hosts on network.


Example: DHCP response spoo1ng
Example: DH CP response spoo 1 ng

• Recall: DHCP used to con 1gure hosts on network.


• DHCP requests broadcast to local network.
• Local attacker can race real server for response, set
victim’s network gateway and DNS server to
attacker-controlled values.
• Allows attacker to act as invisible man-in-the-middle
and relay victim’s traffic.
Network layer threats
Network layer threats

Set arbitrary destination address: No authentication of


traffic sender at network layer

Applications:
• Network scanning:
• Example tools: nmap, zmap, shodan
• IPv4 has 232 possible addresses, possible to enumerate
all of them.
• Send traffic to a port on some protocol, if you get a
response then there is a live service.

• Unwanted trafic:
• Denial of service attacks: overwhelm recipient with
traffic
Network Layer Threats
Network Layer Threats

Misdirection: BGP hijacking.

• Recall: BGP protocol manages IP routing information


between networks on the internet.
• Each BGP node maintains connections to a set of
trusted neighbors.
• Neighbors share routing information.
• Routes are not authenticated: malicious or
malfunctioning nodes may provide incorrect routing
information that redirects IP traffic.
GOVERNMENT OF PAKISTAN
PAKISTAN TELECOMMUNICATION AUTHORITY
ZONAL OFFICE PESHAWAR
Plot-11, Sector A-3, Phase-V, Hayatabad, Peshawar.
Ph: 091-9217279- 5829177 Fax: 091-9217254
[Link]

NWFP-33-16 (BW)/06/PTA February ,2008

Subject: Blocking of Offensive Website

Reference: This office letter of even number dated 22.02.2008.

I am directed to request all ISPs to immediately block access to the following website

URL: [Link]

IPs: [Link], [Link], [Link]


Compliance report should reach this office through return fax or at email
peshawar@[Link] today please.

Deputy Director
To: (Enforcement)
1. M/s Comsats, Peshawar.
2. M/s GO L Internet Services, Peshawar.
3. M/s Cyber Internet, Peshawar.
4. M/s Cybersoft Technologies, Islamabad.
TCP threats
TCP threats
Recall:
• TCP session identified by (source address, source port,
destination address, destination port)
• TCP packets identi1ed by sequence number that
determines where in stream they are placed.

On-path injection
• Connection hijacking: If an on-path attacker knows
ports and sequence numbers, can inject data into the
TCP connection.
• RST injection: Attacker can inject RST into connection to
immediately stop it, will be accepted if sequence
number is within acceptable window.
• Example: China ’s Great Firewall does RST injection to block
tra ffic
Great Firewall of China
Great Firewall of China

• China does extensive monitoring of all cross-border


network tra ffi c and blocks many international services
and sites

• Collection of network techniques and policies called the


“Great Firewall”

• Most famously: RST injection based on IP/host blocking


and deep packet inspection for blacklisted keywords

• Multi-decade arms race on censorship circumvention

• Circumvention techniques: HTTPS, VPNs, proxies, traffic


obfuscation, domain fronting, refraction networking
TCP threats
TCP threats

Blind spoofing: Can an off-path attacker convince a victim


to open a TCP connection with a spoofed host?

• Attacker forges the initial TCP


handshake SYN message from an
arbitrary source.
• The attacker cannot see the SYN-ACK
response so does not learn the
responder ’s sequence number.
TCP threats
TCP threats

Blind spoofing: Can an off-path attacker convince a victim


to open a TCP connection with a spoofed host?

• Attacker forges the initial TCP


handshake SYN message from an
arbitrary source.
• The attacker cannot see the SYN-ACK
response so does not learn the
responder ’s sequence number.
• Initial TCP spec: initial sequence
number based on local clock: easy to
brute force
• Mitigation: use random ISN: 2 −32
chance of guessing correctly.
Application layer threats: DNS spoofing
Application layer threats: DNS spoo fi ng

Recall:
• DNS maps between domain names and IP addresses.
• Responses cached to avoid query times.

DNS Threat Models:


• Malicious DNS server: Any DNS server in query chain
can lie about responses.
Application layer threats: DNS spoofing
Application layer threats: DNS spoo fi ng

Recall:
• DNS maps between domain names and IP addresses.
• Responses cached to avoid query times.

DNS Threat Models:


• Malicious DNS server: Any DNS server in query chain
can lie about responses.
• Local/on-path attacker: Can impersonate DNS server
and send a fake response.
Application layer threats: DNS spoofing
Application layer threats: DNS spoo fi ng

Recall:
• DNS maps between domain names and IP addresses.
• Responses cached to avoid query times.

DNS Threat Models:


• Malicious DNS server: Any DNS server in query chain
can lie about responses.
• Local/on-path attacker: Can impersonate DNS server
and send a fake response.
• Off-path attacker: Can try to forge response: needs to
match 16-bit query ID.
• Original spec: query ID increments with each request.
• Now: Random query ID.
DNS spoo1ng: 2008 Kam insky attack
DNS spoo1ng: 2008 Kaminsky attack
DNS spoo1ng: 2008 Kam insky attack

• Birthday bound: attacker expects to succeed after


28 = 256 lookups
• Mitigation: randomize source port
Conclusion:

• Internet built from protocols that assumed trustworthy


network operators.

• Next lecture: How to add security after the fact.

You might also like