Measuring and Mitigating the Risk of IP Reuse on Public Clouds
Eric Pauley (Pennsylvania State University), Ryan Sheatsley, (Pennsylvania State University), Blaine Hoak (Pennsylvania State University),, Quinn Burke (Pennsylvania State University), Yohan Beugin (Pennsylvania State, University), Patrick McDaniel (Pennsylvania State University)

TL;DR
This paper investigates cloud squatting attacks on public clouds, revealing widespread exploitable configurations, associated risks, and proposing mitigations based on extensive measurements in AWS.
Contribution
It provides the first large-scale measurement and categorization of cloud squatting attacks, identifying vulnerabilities and proposing mitigations for cloud security.
Findings
Over 3 million servers deployed in AWS over 101 days
Identified 5446 exploitable domains including top-ranked ones
Discovered numerous sensitive data leaks and vulnerable configurations
Abstract
Public clouds provide scalable and cost-efficient computing through resource sharing. However, moving from traditional on-premises service management to clouds introduces new challenges; failure to correctly provision, maintain, or decommission elastic services can lead to functional failure and vulnerability to attack. In this paper, we explore a broad class of attacks on clouds which we refer to as cloud squatting. In a cloud squatting attack, an adversary allocates resources in the cloud (e.g., IP addresses) and thereafter leverages latent configuration to exploit prior tenants. To measure and categorize cloud squatting we deployed a custom Internet telescope within the Amazon Web Services us-east-1 region. Using this apparatus, we deployed over 3 million servers receiving 1.5 million unique IP addresses (56% of the available pool) over 101 days beginning in March of 2021. We…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsCloud Data Security Solutions · Information and Cyber Security · Network Security and Intrusion Detection
