Patch Pilgrimage: Exploring the Landscape of TCP Reflective Attacks and User Patching Expedition

Joost Oortwijn, Carlos Gañán · 2024

The proliferation of Internet-connected devices has led to a concerning increase in cyberattacks. Among these, a novel attack technique has emerged, which involves the use of TCP reflective amplification attacks to launch large-scale Distributed Denial of Service (DDoS) assaults. This technique has proven to be more effective than UDP-based amplifiers, underscoring the pressing need for immediate attention. In this study, we delve into the heart of this vulnerability by examining the characteristics of vulnerable devices and the security practices of their users. Our findings highlight two critical aspects: first, devices can remain unpatched for extended periods, and second, their amplification rates can exceed those of traditional DDoS amplification vectors. Through network scans, we identified over 30,000 vulnerable devices within a single Internet Service Provider (ISP). These devices encompass a wide range of types, from alarm systems to energy monitors. In collaboration with the ISP, we conducted semi-structured interviews with the users of these vulnerable devices. Our interviews revealed that while vulnerability notifications have the potential to motivate end-users to update their devices, comprehensive descriptions are essential for accurate identification and the subsequent implementation of necessary software and firmware updates.

Read the paper · More papers on PaperTik