StateShield: Real-Time Defenses Against Information Leakage Over Connectionless Protocols

Haibin Li, Qi Lecky Li, Yingying Su, Xuewei Feng, Chuanpu Fu, Ke Xu · IEEE Transactions on Networking · 2025

Connectionless protocols such as ICMP and UDP are manipulated to construct novel information leakage channels by which attackers can disrupt TCP connections or leak secret information. Existing solutions have mainly focused on repairing vulnerable protocols through OS patches, which are OS-specific and slow to deploy. Other traditional defenses either cannot cover these attacks or are prone to incur unintended dropping of legitimate packets due to the heavily manipulated IP spoofing technique in these attacks. In this paper, we present StateShield, an in-network, real-time defense against state-of-the-art information leakage attacks over connectionless protocols. StateShield can detect and defend against various information leakage attacks without incurring unintended dropping of legitimate traffic, even when attackers heavily spoof the IP addresses of legitimate clients. To achieve that, we propose three indicators that can cover major attack vectors of connectionless information leakage channels and are effective for detecting more than ten attack variants. We design the architecture of StateShield based on programmable switches, with efficient data structures for monitoring and on-demand defense components in the data plane. We develop two novel defense components to mitigate UDP and ICMP-based information leakage channels automatically while achieving minimal unintended dropping of legitimate packets. Our extensive experiments show that StateShield can effectively mitigate more than ten attack variants in real time without hurting the services over legitimate connectionless packets, and the defense provided by StateShield is robust under high-intensive background traffic over connectionless protocols.

Read the paper · More papers on PaperTik