论文标题

您的路由器是我的Prober:通过ICMP限制侧渠道测量IPv6网络

Your Router is My Prober: Measuring IPv6 Networks via ICMP Rate Limiting Side Channels

论文作者

Pan, Long, Yang, Jiahai, He, Lin, Wang, Zhiliang, Nie, Leyao, Song, Guanglei, Liu, Yaozhong

论文摘要

当某些测量值需要许多远程优势点时,主动的互联网测量结果面临挑战。在本文中,我们提出了一种新型技术,用于通过ICMP速率限制的侧通道测量远程IPv6网络,这是IPv6节点的必需功能,以限制生成ICMP错误消息的速率。这种技术在某种程度上可以使用在9.5k自主系统和182个国家 /地区作为我们的“有利位置”中分布在9.5k自主系统和182个国家的偏远路由器。我们将ivantage应用于两种不同的,但两者都具有挑战性的测量任务:1)测量入站源地址验证(ISAV)的部署(ISAV)和2)测量任意互联网节点之间的可达到性。我们只能从一个本地优势点完成这两个任务,而无需控制目标或依靠目标网络中的其他服务。我们的大规模ISAV测量范围占所有IPv6自主系统的50%,发现其中约79%的人容易受到欺骗的影响,这是迄今为止IPv6 ISAV的最大规模测量研究。我们的可及性测量方法在评估中实现了超过80%的精度和回忆。最后,我们对ICMP利率限制实现进行了互联网范围的测量,对ICMP利率限制的详细讨论,尤其是ICMP限制机制的潜在安全性和隐私风险,并提供可能的缓解措施。我们将代码提供给社区。

Active Internet measurements face challenges when some measurements require many remote vantage points. In this paper, we propose a novel technique for measuring remote IPv6 networks via side channels in ICMP rate limiting, a required function for IPv6 nodes to limit the rate at which ICMP error messages are generated. This technique, iVantage, can to some extent use 1.1M remote routers distributed in 9.5k autonomous systems and 182 countries as our "vantage points". We apply iVantage to two different, but both challenging measurement tasks: 1) measuring the deployment of inbound source address validation (ISAV) and 2) measuring reachability between arbitrary Internet nodes. We accomplish these two tasks from only one local vantage point without controlling the targets or relying on other services within the target networks. Our large-scale ISAV measurements cover ~50% of all IPv6 autonomous systems and find ~79% of them are vulnerable to spoofing, which is the most large-scale measurement study of IPv6 ISAV to date. Our method for reachability measurements achieves over 80% precision and recall in our evaluation. Finally, we perform an Internet-wide measurement of the ICMP rate limiting implementations, present a detailed discussion on ICMP rate limiting, particularly the potential security and privacy risks in the mechanism of ICMP rate limiting, and provide possible mitigation measures. We make our code available to the community.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源