Analysis of security vulnerabilities and countermeasures of CDN in Satellite Internet
Received date: 2024-06-25
Online published: 2024-11-16
Copyright
With the development of Satellite Internet technology, content delivery network (CDN) with the integrated satellite- terrestrial environment plays a significant role in enhancing the experience of information access and alleviating the stress on the Internet's backbone. However, CDN in Satellite Internet also faces a series of security vulnerabilities. The vulnerabilities of CDN in Satellite Internet were analyzed and the corresponding countermeasures were discussed, delving into the security issues of content distribution in Satellite Internet. Based on this, a series of difficulties to enhance the security mechanism of CDN in Satellite Internet were proposed and the security threats of CDN in Satellite Internet were summarized, providing an outlook for future research directions.
LIU Jun , LI Hewu . Analysis of security vulnerabilities and countermeasures of CDN in Satellite Internet[J]. Journal of Cybersecurity, 2024 , 2(4) : 53 -65 . DOI: 10.20172/j.issn.2097-3136.240405
表 1 卫星CDN主要安全威胁总结Table 1 Major security threats to satellite CDN |
| 安全威胁 | 原因 | 实施手段 | 常见目的 | 严重程度 | ||
| 中继 | 缓存 | 缓存+源 | ||||
| 地址欺骗攻击 | IP协议不检查地址真实性 | 伪造报文源地址欺骗网络设备 | 拒绝服务攻击(DoS)或窃取敏感信息 | 升高 | 升高 | 升高 |
| 路由攻击 | 中间节点和目的端不检查转发路径 | 伪造路由器的信息或者劫持路由器篡改路由表 | 数据包丢失或者流向错误的目的地,造成拒绝服务攻击或者数据泄露 | 升高 | 降低 | 降低 |
表 2 卫星CDN安全威胁严重程度Table 2 Severity of cybersecurity threats for satellite CDN |
| 安全威胁 | 威胁模型 | 严重程度 | ||
| 中继 | 缓存 | 缓存+源 | ||
| ①拒绝服务(边缘) | 随机字符串或动态请求 | 持平 | 降低 | 降低 |
| ②降低缓存命中 | 缓存污染 | 持平 | 升高 | 升高 |
| ③隐蔽传输 | CDN隐蔽通道攻击 | 持平 | 降低 | 降低 |
| ④源站暴露 | DNS历史记录;对邮件、FTP和SSH等非Web服务对应的子域执行字典攻击;维护或迁移服务的暂时暴露;诱使源服务器建立与攻击者直连的出站连接 | 持平 | 持平 | 持平 |
| ⑤破解地理限制 | CDN源滥用 | 持平 | 升高 | 升高 |
| ⑥边缘缓存服务器地址泄露 | 入口IP侦查 出口IP侦查 | 持平 | 升高 | 升高 |
| ⑦拒绝服务(路由) | 转发环路 | 持平 | 持平 | 持平 |
| 出口阻塞 | 持平 | 降低 | 持平 | |
| 重定向 | 持平 | 降低 | 降低 | |
| ⑧窃取数据 | 路由劫持 | 持平 | 升高 | 升高 |
表 3 卫星CDN安全机制及脆弱性总结Table 3 Security mechanisms and vulnerabilities of satellite content delivery network |
| 安全威胁 | 安全机制 | 机制脆弱性 |
| ①拒绝服务(边缘) | ①基于协作的检测 | 恶意用户使用虚假IP混淆检测 |
| ②降低缓存命中 | ①基于攻击者的检测 ②基于对象的检测 | 恶意用户通过不断伪造新的IP,伪装成不同的用户,使统计检测失效 |
| ③隐蔽传输 | ①基于令牌 ②随机化第一跳与最后一跳缓存服务器的映射 | 恶意用户通过伪造IP,利用路由服务器规则接入特定边缘服务器;路径随机化可能导致绕路降低性能,并掩盖路由劫持攻击 |
| ④源站暴露 | ①基于代理 ②基于白名单 | 代理增加了边缘缓存服务器的负载,占用带宽,引入新的DDos风险;恶意用户可伪造白名单中的IP |
| ⑤破解地理限制 | 源站锁定 | 源站与CDN的连接动态性使得持续探测源站凭证文件,增加了状态转移的相关开销;上传文件步骤或引入新的DoS攻击面 |
| ⑥边缘缓存服务器地址泄露 | ①绑定拆分 ②主动代理迁移 | 星地动态性下难以建立稳定的用户-边缘服务器绑定关系,恶意用户天然遍历大量卫星节点 |
| ⑦拒绝服务(路由) | ①标头监视 ②环路检测 | 恶意用户使用虚假IP规避过滤;需要所有CDN节点都使用CDN-Loop 标头才有效,否则无法感知转发路径异常 |
| 分配更多的出口IP与源服务器连接 | 将请求转发分布在更多出口边缘服务器上会降低聚合性,浪费缓存 | |
| ①DNS安全扩展(DNSSEC)协议 ②请求重映射 ③清洗中心 ④限制同一源IP的相同查询的 DNS 响应速率 | ①动态记录签名的高计算成本使DNSSEC难以部署 ②测量增加额外时延 ③分流过程占用大量星间带宽 ④恶意用户使用大量虚假IP发起查询规避DNS响应限制 | |
| ⑧窃取数据 | 路径验证 | 动态网络路径时变导致高验证开销 |
| 1 |
THOMAS B,SHRUTI J,USHA A,et al. Cisco visual networking index (VNI) complete forecast update,2017–2022[EB/OL]. (2018-12-01) [2024-06-22]. https://bit.ly/2KvbhWL.
|
| 2 |
CISCO. Cisco visual networking index:Forecast and trends,2017-2022[EB/OL]. (2022-02-19) [2024-06-22]. https://cloud.report/Resources/Whitepapers/eea79d9b-9fe3-4018-86c6-3d1df813d3b8_white-paper-c11-741490.pdf.
|
| 3 |
LAI Z,LI H,ZHANG Q,et al. Cooperatively constructing cost-effective content distribution net-works upon emerging low earth orbit satellites and clouds[C]//2021 IEEE 29th International Conference on Network Protocols (ICNP). 2021:1-12.
|
| 4 |
WALDSPURGER C A,PARK N,GARTHWAITE A,et al. Efficient mrc construction with shard[C]//13th USENIX Conference on File and Storage Technologies. 2015:95-110.
|
| 5 |
PASCHOS G S, IOSIFIDIS G, TAO M, et al. The role of caching in future communication systems and networks[J]. IEEE Journal on Selected Areas in Communications, 2018, 36 (6): 1111- 1125.
|
| 6 |
李贺武, 吴茜, 徐恪, 等. 天地一体化网络研究进展与趋势[J]. 科技导报, 2016, 34 (14): 95- 106.
LI H W, WU Q, XU K, et al. Progress and tendency of space and earth integrated network[J]. Science & Technology Review, 2016, 34 (14): 95- 106.
|
| 7 |
BHATTACHERJEE D,SINGLA A. Network topology design at 27,000 km/hour[C]//Proceedings of the 15th International Conference on Emerging Networking Experiments And Technologies. 2019:341-354.
|
| 8 |
LI Y,LI H,LIU L,et al. “internet in space” for terrestrial users via cyber-physical convergence [C]//Proceedings of the Twentieth ACM Workshop on Hot Topics in Networks. 2021:163-170.
|
| 9 |
GIULIARI G, KLENZE T, LEGNER M, et al. Internet backbones in space[J]. ACM SIGCOMM Computer Communication Review, 2020, 50 (1): 25- 37.
|
| 10 |
HAURI Y,BHATTACHERJEE D,GROSSMANN M,et al. “internet from space” without inter-satellite links[C]//Proceedings of the 19th ACM Workshop on Hot Topics in Networks. 2020:205-211.
|
| 11 |
LAI Z,WU Q,LI H,et al. Orbitcast:Exploiting mega-constellations for low-latency earth observation [C]//2021 IEEE 29th International Conference on Network Protocols. 2021:1-12.
|
| 12 |
SPACEX. Starlink[EB/OL]. (2024-06-22) [2024-06-22]. https://www.starlink.com/.
|
| 13 |
AMAZON. Kuiper[EB/OL]. (2024-06-22) [2024-06-22]. https://www.geekwire.com/2019/amazon-proje ct-kuiper-broadband-satellite/.
|
| 14 |
ONEWEB. Oneweb[EB/OL]. (2024-06-22) [2024-06-22]. https://oneweb.net/.
|
| 15 |
PACHLER N,DEL PORTILLO I,CRAWLEY E F,et al. An updated comparison of four low earth orbit satellite constellation systems to provide global broadband [C]//2021 IEEE International Conference on Communications Workshops. IEEE,2021:1-7.
|
| 16 |
SPACEBELT. SpaceBelt cloud constellation corporation[EB/OL]. (2024-06-22) [2024-06-22]. https://spacebelt.com/partners/.
|
| 17 |
BHATTACHERJEE D,AQEEL W,BOZKURT I N,et al. Gearing up for the 21st century space race[C]//Proceedings of the 17th ACM Workshop on Hot Topics in Networks. 2018:113-119.
|
| 18 |
HANDLEY M. Delay is not an option:Low latency routing in space[C]//Proceedings of the 17th ACM Workshop on Hot Topics in Networks. 2018:85-91.
|
| 19 |
HANDLEY M. Using ground relays for low-latency wide-area routing in megaconstellations [C]//Proceedings of the 18th ACM Workshop on Hot Topics in Networks. 2019:125-132.
|
| 20 |
KALANTARI A,FITTIPALDI M,CHATZ INOTAS S,et al. Cache-assisted hybrid satellite-terrestrial back-hauling for 5g cellular networks [C]//IEEE Global Communications Conference. 2017:1-6.
|
| 21 |
VU T X, POIRIER Y, CHATZINOTAS S, et al. Modeling and implementation of 5G edge caching over satellite[J]. International Journal of Satellite Communications and Networking, 2020, 38 (5): 395- 406.
|
| 22 |
LUGLIO M, ROMANO S P, ROSETI C, et al. Service delivery models for converged satellite-terrestrial 5G network deployment: A satellite-assisted cdn use-case[J]. IEEE Network, 2019, 33 (1): 142- 150.
|
| 23 |
CSC. Shine (secure hybrid in network caching environment) security and content rights management in satellite assisted in network caching systems[EB/OL]. (2024-06-22) [2024-06-22]. https://artes.esa.int/projects/shine-secure-hybrid-network-caching-environment.
|
| 24 |
WU H,LI J,LU H,et al. A two-layer caching model for content delivery services in satellite-terrestrial networks[C]//IEEE Global Communications Conference. 2016:1-6.
|
| 25 |
ZHU X, JIANG C, KUANG L, et al. Cooperative multilayer edge caching in integrated satellite-terrestrial networks[J]. IEEE Transactions on Wireless Communications, 2021, 21 (5): 2924- 2937.
|
| 26 |
JIANG D, WANG F, LV Z, et al. Qoe-aware efficient content distribution scheme for satellite-terrestrial networks[J]. IEEE Transactions on Mobile Computing, 2021, 22 (1): 443- 458.
|
| 27 |
YANG S,LI H,LAI Z,et al. A synergic architecture for content distribution in integrated satellite and terrestrial networks[C]//2020 IEEE/CIC International Conference on Communications in China (ICCC). IEEE,2020:96-101.
|
| 28 |
央视网. 中国空间站第三次太空授课活动取得圆满成功[EB/OL]. (2022-10-22) [2024-06-22]. http://news.cctv.com/2022/10/12/ARTIwrrzDXC52sFH9JBuYf9L221012.shtml.2022.
CCTV. China's Space Station successfully completes Its third space teaching activity[EB/OL]. (2022-10-22) [2024-06-22]. http://news.cctv.com/2022/10/12/ARTIwrrzDXC52sFH9JBuYf9L221012.shtml.2022.
|
| 29 |
International Cospas-Sarsat Programme. Cospas-sarsat system[EB/OL]. (2024-06-22) [2024-06-22]. https://cospas-sarsat.int/en/system-overview/cospas-sarsat-system.
|
| 30 |
SPACEX. Starshield[EB/OL]. (2024-06-22) [2024-06-22]. https://www.spacex.com/starshield/.
|
| 31 |
GHAZNAVI M, JALALPOUR E, SALAHUDDIN M A, et al. Content delivery network security: A survey[J]. IEEE Communications Surveys & Tutorials, 2021, 23 (4): 2166- 2190.
|
| 32 |
MUBAROK I,LEE K,LEE S,et al. Lightweight resource management for DDoS traffic isolation in a cloud environment[C]//ICT Systems Security and Privacy Protection:29th IFIP TC 11 International Conference,2014:44-51.
|
| 33 |
KETTLE J. Practical web cache poisoning.[EB/OL]. (2018-08-09) [2024-06-22]. https://bit.ly/ 39nCTab.
|
| 34 |
AMIT K. Web cache poisoning attacks[EB/OL]. (2011-01-01) [2024-06-22]. https://link.springer.com/referenceworkentry/10.1007/978-1-4419-5906-5_666.
|
| 35 |
MIRHEIDARI S A,ARSHAD S,ONARLIOGLU K,et al. Cached and confused:Web cache deception in the wild[C]//29th USENIX Security Symposium (USENIX Security 20). 2020:665-682.
|
| 36 |
PARK H,WIDJAJA I,LEE H. Detection of cache pollution attacks using randomness checks[C]//2012 IEEE International Conference on Communications (ICC). IEEE,2012:1096-1100.
|
| 37 |
JON L. How cloudflare protects customers from cache poisoning[EB/OL]. (2018-08-20) [2024-06-22]. https://blog.cloudflare.com/cache-poisoning-protection/.
|
| 38 |
INVICTI,On Web cache deception attacks[EB/OL]. (2024-04-18) [2024-06-22]. https://www. invicti.com/web-vulnerability-scanner/vulnerabilities/ web-cache-deception/.
|
| 39 |
CHEUNG K H. Web cache deception attack revisited[EB/OL]. (2018-01-19) [2024-06-22]. https://blog.cloudflare.com/web-cache-deception-attack-revisited.
|
| 40 |
NGUYEN H V,IACONO L L,FEDERRATH H. Your cache has fallen:Cache-poisoned denial-of-service attack[C]//Proceedings of the 2019 ACM SIGSAC Conference on Computer and Commun ications Security. 2019:1915-1936.
|
| 41 |
REBLAZE W. CPDoS Attack.[EB/OL]. (2023-03-05)[2024-06-22]. https://www.reblaze.com/wiki/ ddos/cpdos-attack/.
|
| 42 |
LALKAKA R. Cloudflare response to CPDoS exploits[EB/OL]. (2019-10-24) [2024-06-22]. https://bit.ly/2U4Tnzy.
|
| 43 |
JOSHUA L. Understanding our cache and the web cache deception attack[EB/OL]. (2017-04-14) [2024-06-22]. https://bit.ly/3cbmw3n.
|
| 44 |
FIELDING R,RESCHKE J. Hypertext transfer protocol[EB/OL]. (2014-06-01) [2024-06-22]. http://www.rfc-editor.org/rfc/rfc7231.txt.
|
| 45 |
DESMEDT Y. Covert channels[EB/OL].( 2011-06-29) [2024-06-22]. https://doi.org/10.1007/978-1-4419-5906-5_315.
|
| 46 |
WANG Y, SHEN Y, JIAO X, et al. Exploiting content delivery networks for covert channel communications[J]. Computer Communications, 2017, 99, 84- 92.
|
| 47 |
VENKATESAN S,ALBANESE M,AMIN K,et al. A moving target defense approach to mitigate DDoS attacks against proxy-based architectures[C]//2016 IEEE Conference on Communications and Network Security (CNS). IEEE,2016:198-206.
|
| 48 |
GUO R,LI W,LIU B,et al. CDN Judo:Breaking the CDN DoS Protection with Itself[C]//NDSS. 2020.
|
| 49 |
JIN L,HAO S,WANG H,et al. Unveil the hidden presence:Characterizing the backend interface of content delivery networks[C]//2019 IEEE 27th International Conference on Network Protocols (ICNP). IEEE,2019:1-11.
|
| 50 |
KANG M S,LEE S B,GLIGOR V D. The crossfire attack[C]//2013 IEEE symposium on security and privacy. IEEE,2013:127-141.
|
| 51 |
IETF RFC 7230. Hypertext transfer protocol (HTTP/1.1):Message syntax and routing [S]. Fremont,CA:Fielding R and Reschke J,2014-06.
|
| 52 |
GUO R,CHEN J,LIU B,et al. Abusing CDNs for fun and profit:Security issues in CDNs' origin validation[C]//2018 IEEE 37th Symposium on Reliable Distributed Systems (SRDS). IEEE,2018:1-10.
|
| 53 |
CHEN J,ZHENG X,DUAN H X,et al. Forwarding-Loop Attacks in Content Delivery Networks[C]//NDSS. 2016.
|
| 54 |
IETF RFC 8586. Loop detection in content delivery networks (CDNs) [S]. Fremont,CA:Ludin S,Nottingham M,and Sullivan N,2019-04.
|
| 55 |
IETF RFC 4033. DNS security introduction and requirements [S]. Fremont,CA:Arends R,Austein R,Larson M,et al,2005-05.
|
| 56 |
PERDISCI R,ANTONAKAKIS M,LUO X,et al. WSEC DNS:Protecting recursive DNS resolvers from poisoning attacks[C]//2009 IEEE/IFIP International Conference on Dependable Systems & Networks. IEEE,2009:3-12.
|
| 57 |
JIN L,HAO S,WANG H,et al. Your remnant tells secret:Residual resolution in ddos protection services[C]//2018 48th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN). IEEE,2018:362-373.
|
| 58 |
JIA Q,WANG H,FLECK D,et al. Catch me if you can:A cloud-enabled DDoS defense[C]//2014 44th Annual IEEE/IFIP International Conference on Dependable Systems and Networks. IEEE,2014:264-275.
|
| 59 |
IETF RFC 4254. The secure shell (SSH) connection protocol [S]. Fremont,CA:Ylonen T,Lonvick C,2006-01.
|
| 60 |
BUTLER T. Analysis of a Wordpress Pingback DDoS Attack[EB/OL]. (2016-11-25) [2024-06-22]. https://bit.ly/2VL9OAP.
|
| 61 |
PRINCE M. Introducing CNAME Flattening:RFC-Compliant CNAMEs at a Domain’ S Root[EB/OL]. (2014-04-03) [2024-06-22]. https://bit.ly/2XFiPz8.2014.
|
/
| 〈 |
|
〉 |