Elias Heftrig

dblp:279/5630 · DBLP profile ↗
← Back
7ranked-venue papers
5as first author
6since 2021 · last 2024
0000-0002-6225-7835ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 4 first-author · 5 since 2021Computer networks · 2 · 1 first-author · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021
YearPublicationVenuePosition
2024 The Harder You Try, The Harder You Fail: The KeyTrap Denial-of-Service Algorithmic Complexity Attacks on DNSSEC
abstract
Availability is a major concern in the design of DNSSEC. To ensure availability, DNSSEC follows Postel's Law [RFC1123]: "Be liberal in what you accept, and conservative in what you send." Hence, nameservers should send not just one matching key for a record set, but all the relevant cryptographic material, e.g., all the keys for all the ciphers that they support and all the corresponding signatures. This ensures that validation succeeds, and hence availability, even if some of the DNSSEC keys are misconfigured, incorrect or correspond to unsupported ciphers.
Elias Heftrig, Haya Schulmann, Niklas Vogel, Michael Waidner
CCS1
2023 Poster: Off-Path DNSSEC Downgrade Attacks
abstract
Recent works found that signing zones with new cryptographic ciphers may disable DNSSEC validation in DNS resolvers. Adversaries could exploit this to manipulate algorithm numbers of ciphers in DNS responses, to make them appear as unknown, hence maliciously downgrading DNSSEC validation. In this work we show that these manipulation of DNSSEC records can also be launched remotely by off-path adversaries. We develop a DNSSEC downgrade attack using IP fragmentation. The idea is to create large DNS responses, that exceed the Maximum Transmission Unit on that path. The off-path adversary injects a malicious IP fragment, which when reassembled with the genuine IP fragment, overwrites the algorithm number of the ciphers in DNSSEC records.
Elias Heftrig, Haya Schulmann, Michael Waidner
SIGCOMM1
2023 Downgrading DNSSEC: How to Exploit Crypto Agility for Hijacking Signed Zones
Elias Heftrig, Haya Schulmann, Michael Waidner
USENIX Security Symposium1
2022 Poster: The Unintended Consequences of Algorithm Agility in DNSSEC
abstract
Cryptographic algorithm agility is an important property for DNSSEC: it allows easy deployment of new algorithms if the existing ones are no longer secure. In this work we show that the cryptographic agility in DNSSEC, although critical for provisioning DNS with strong cryptography, also introduces a vulnerability. We find that under certain conditions, when new algorithms are listed in signed DNS responses, the resolvers do not validate DNSSEC. As a result, domains that deploy new ciphers may in fact cause the resolvers not to validate DNSSEC. We exploit this to develop DNSSEC-downgrade attacks and experimentally and ethically evaluate them against popular DNS resolver implementations, public DNS providers, and DNS services used by web clients worldwide. We find that major DNS providers as well as 45% of DNS resolvers used by web clients are vulnerable to our attacks.
Elias Heftrig, Haya Schulmann, Michael Waidner
CCS1
2021 Predictive Cipher-Suite Negotiation for Boosting Deployment of New Ciphers
abstract
Deployment of strong cryptographic ciphers for DNSSEC is essential for long term security of DNS. Unfortunately, due to the hurdles involved in adoption of new ciphers coupled with the limping deployment of DNSSEC, most domains use the weak RSA-1024 cipher.
Elias Heftrig, Jean-Pierre Seifert, Haya Schulmann, Michael Waidner, Nils Wisiol
CCS1
2021 The Master and Parasite Attack
abstract
We explore a new type of malicious script attacks: the persistent parasite attack. Persistent parasites are stealthy scripts, which persist for a long time in the browser's cache. We show to infect the caches of victims with parasite scripts via TCP injection. Once the cache is infected, we implement methodologies for propagation of the parasites to other popular domains on the victim client as well as to other caches on the network. We show how to design the parasites so that they stay long time in the victim's cache not restricted to the duration of the user's visit to the web site. We develop covert channels for communication between the attacker and the parasites, which allows the attacker to control which scripts are executed and when, and to exfiltrate private information to the attacker, such as cookies and passwords. We then demonstrate how to leverage the parasites to perform sophisticated attacks, and evaluate the attacks against a range of applications and security mechanisms on popular browsers. Finally we provide recommendations for countermeasures.
Lukas Baumann, Elias Heftrig, Haya Schulmann, Michael Waidner
DSN2
2020 Black-box caches fingerprinting
abstract
We propose the first methodologies for remotely inferring and fingerprinting the software of DNS caches in the Internet based solely on the exchange of queries/responses with the DNS platform. Our techniques are robust and cannot be altered in transit, e.g., by firewalls, which does not hold for the existing fingerprinting techniques. In particular, the only way to alter the outcome of our fingerprinting methods is by modifying the DNS software itself.
Amit Klein 0001, Elias Heftrig, Haya Schulmann, Michael Waidner
CoNEXT2