TCP Injections for Fun and Clogging
Yossi Gilad, Amir Herzberg

TL;DR
This paper introduces off-path TCP injection-based clogging DoS attacks that can be executed with minimal requirements, such as sandboxed JavaScript, to cause large-scale network disruptions, highlighting the need for cryptographic defenses.
Contribution
The paper presents novel off-path TCP injection techniques that require only sandboxed JavaScript, enabling large-scale clogging DoS attacks against third parties, with improved attack efficiency and modular design.
Findings
Achieved high amplification factors with off-path attacks
Injected TCP segments using only sandboxed JavaScript
Demonstrated effectiveness in clogging third-party networks
Abstract
We present a new type of clogging DoS attacks, with the highest amplification factors achieved by off-path attackers, using only puppets, i.e., sandboxed malware on victim machines. Specifically, we present off-path variants of the Opt-ack, Ack-storm and Coremelt DoS attacks, achieving results comparable to these achieved previously achieved by eavesdropping/MitM attackers and (unrestricted) malware. In contrast to previous off-path attacks, which attacked the client (machine) running the malware, our attacks address a very different goal: large-scale clogging DoS of a third party, or even of backbone connections. Our clogging attacks are based on off-path TCP injections. Indeed, as an additional contribution, we present improved off-path TCP injection attacks. Our new attacks significantly relax the requirements cf. to the known attacks; specifically, our injection attack requires…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInternet Traffic Analysis and Secure E-voting · Network Security and Intrusion Detection · Advanced Malware Detection Techniques
