Attacking TTL-based "authentication"

Tomasz Grabowski <[email protected]> Fri, 17 Oct 2003 22:53:54 +0200 (CEST)
Newsgroups gmane.ietf.itrace
Message-ID <[email protected]>
We need to clarify this one, before we could move further.


On Fri, 17 Oct 2003, Mikael Olsson wrote:

> You're missing the point. If I receive a packet with TTL 252, I
> know for a fact that it was generated by a host no more than three
> hops out. This is undeniable. Using this logic, you can reconstruct
> itrace chains with a "fair" degree of probability.  This was the
> essence of the original itrace proposal.


Pekka Savola wrote:

>So, for reasonably local tracing, setting TTL=255 for outgoing iTraces
>should work just fine.  For global tracing, the attackers could try to
>guess the how many hops away the iTrace inspector is from the routers
>sending iTrace and do some iTrace injection of their own.

>The point here, however, is that you don't do anything if you don't
>receive *coherent* *trace* of itraces, e.g. every router, with increasing
>hop-count, sends you about the same amount of itraces regularly.  Weeding
>out wrong itraces from that should not be a huge problem.

>But this kind of security model would need more thinking, of course.


You are trying to tell me that it is impossible to spoof that TTL-based
authentication?

Let's consider two situations:
1. Some routers in Internet (range from 1 to all_routers_in_Internet-1)
   have iTrace implemented.
2. All routers in Internet have iTrace implemented.

Situation 2 is nearly impossible to achive, but if it is possible to
make a successfull attack in that situation, it will be possible to attack
situation 1 as well, right?


So, let's attack situation 2:


                   ,-----[R7]---[R8]----{Innocent}
                   |
                   |
{Victim}---[R1]---[R2]---[R3]---{Attacker1}
            |
            |
            '-----[R4]---[R5]---[R6]---{Attacker2}



Victim - victim of DDoS attack
Attacker1 and Attacker2 - DDoS agents that are actually doing DDoS attack
Innocent - some regular computer not involved in DDoS attack
R1 - R8 - routers with iTrace support

So, Attackers are attacking Victim. Routers from R1 to R6 are generating
iTrace messages. Victim can collect them and make a path to Attacker1 and
Attacker2 with "fair degree of probability".

Attacker wants to trick Victim into thinking that Innocent is involved in
this DDoS attack as well. What should she do (in other words: how this
attack will vary from todays DDoS attacks)?

She needs to find a computer as close as possible to Victim. In this
scenario it need to be something connected to R1, R2, R4, R7 or R8.
Gaining access to something connected to R1 making her able to spoof
virtually any router in Internet (from the Victim point of view of
course).

Assuming she is connected to R4 (worst case) she needs to send such iTrace
packets:
1. src: R8   TTL=254
2. src: R7   TTL=255
She can't send iTrace packets on behalf of R2 and R1 but it's not so
important because in this scenario these routers will generate iTrace
messages by themselves.

Assuming she is connected to R1 (best case) she needs to send such iTrace
packets:
1. src: R8   TTL=253
2. src: R7   TTL=254
3. src: R2   TTL=255

How Victim can recognize that these packets were forged?


Have on mind that:
- Internet is more complicated that my diagram
- In real life we will be dealing with Situation 1, so it will not be
  necessary to spoof all routers in the chain



---
Tomasz Grabowski  (0-91)4494234
Akademickie Centrum Informatyki
mailto:[email protected]