An empirical evaluation of misconfiguration in Internet services

Tobias Fiebig · DepositOnce · 2017

Within the past thirty years we have seen computers rise from room sized niche equipment to handy pocket sized devices found in every household. At the same time there has been a significant increase in the research effort on computer security. The literature is full of sophisticated attacks to obtain confidential information from computer systems, compromise them, or prevent them from being used at all. Simultaneously, mitigations to these attacks are as well studied. Technically, current attacks could be mitigated by deploying these techniques. In fact, there is a constant stream of new, complex techniques to ensure the confidentiality, integrity, and availability of data and systems. However, even the recent past has not been short of security incidents affecting billions of people. Yet, these incidents are usually neither enabled nor mitigated by these complex techniques. On the contrary, we find that these breaches are usually caused by something far more simple: Human error in deploying and running network services, e.g., delayed software updates, or, no authentication and authorization being configured even though it would have been available. We refer to these as security misconfigurations. In this thesis we empirically investigate the nature of security misconfigurations. Specifically, to approach the unscoped question, if and how security misconfigurations introduce challenges to the security of Internet services, we investigate: (i) What are security misconfigurations (in Internet Services), (ii) How we can measure security misconfigurations, and, (iii) How security misconfigurations can be measured and mitigated in today’s as well as tomorrow’s IPv6 Internet. We find that complex attacks are commonly prevented by easy to implement technical mitigations. In contrast, misconfiguration based issues require a more demanding approach that is focused on the personnel operating Internet services. Patching humans is incredibly hard. Furthermore, our literature study indicates that there are already problems in the design of protocols. A good design can prevent misconfigurations, while a bad design can lead to multiple, easily misconfigured implementations. Current mitigation techniques are focused on identifying and contacting affected operators, so they can take appropriate action and remove the misconfiguration. However, this process heavily relies on security scans of the whole Internet. While this is feasible with IPv4, the current Internet Protocol Version, a similar bruteforce approach is unfeasible for the larger address space of the upcoming IPv6. Hence, we develop and evaluate a new methodology that enables researchers to perform security scans of IPv6 connected hosts. Hence, in summary, this thesis outlines the first steps towards addressing security misconfigurations as an Internet wide issue with an exploratory approach rooted in empirical measurements. We conclude this work by discussing various paths of future research, which should be pursued to reduce the impact of security misconfigurations on the Internet.

Read the paper · More papers on PaperTik