Subverting Stateful Firewalls with Protocol States
Amit Klein · 2022
We analyzed the generation of protocol header fields in the implementations of multiple TCP/IP network stacks and found new ways to leak information about global protocol states.We then demonstrated new covert channels by remotely observing and modifying the system's global state via these protocol fields.Unlike earlier works, our research focuses on hosts that reside in firewalled networks (including source address validation -SAV), which is a very common scenario nowadays.Our attacks are designed to be non-disruptive -in the exfiltration scenario, this makes the attacks stealthier and thus extends their longevity, and in case of host alias resolution and similar techniques -this ensures the techniques are ethical.We focused on ICMP, which is commonly served by firewalls, and on UDP, which is forecasted to take a more prominent share of the Internet traffic with the advent of HTTP/3 and QUIC, though we report results for TCP as well.The information leakage scenarios we discovered enable the construction of practical covert channels which directly pierce firewalls, or indirectly establish communication via hosts in firewalled networks that also employ SAV.We describe and test three novel attacks in this context: exfiltration via the firewall itself, exfiltration via a DMZ host, and exfiltration via co-resident containers.These are three generic, new use cases for covert channels that work around firewalling and enable devices that are not allowed direct communication with the Internet, to still exfiltrate data out of the network.In other words, we exfiltrate data from isolated networks to the Internet.We also explain how to mount known attacks such as host alias resolution, de-NATting and container co-residence detection, using the new information leakage techniques.In this research, we focus on server de-NATting, meaning, discerning whether two external endpoints refer to the same host or to two different hosts.This is in contrast to client de-NATting, which refers to discerning whether two outbound connections (designated by their external address endpoints) are made by a single client or by two different clients.The material difference is that a NATted client is likely to use a single internal IP address, whereas a NATted server may use two IP addresses for two different services.Some operating systems use the (IP SRC , IP DST ) tuple to generate network fields, making it trivial to de-NAT clients, but not servers. Co-Residency Detection for Containers[39] is a concept similar to host alias detection, which aims to detect whether two endpoints on two different containers are hosted by the same physical host.If virtualization is used, then the containers may run on two different virtual machines.We are interested in a variant of this concept, which is to detect whether two endpoints on two different containers are hosted by the same operating system kernel.Container technology (e.g.Docker) is available for Linux and Windows.Our co-residency detection attacks apply to Linux, but not to Windows. 1 The IPv4 DF ("Don't Fragment") header flag controls fragmentation by routers.Setting DF=1 prohibits routers from fragmenting the packet.