Yepeng Pan

dblp:381/1650 · DBLP profile ↗
← Back
3ranked-venue papers
3as first author
3since 2021 · last 2025
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 3 first-author · 3 since 2021
YearPublicationVenuePosition
2025 GET /large. file HTTP /1.1: Connection-Based TCP Amplification Attacks
abstract
Amplification Denial-of-Service (DoS) attacks steer high-volumetric traffic to a victim by sending small IP-spoofed requests to UDP-based services. An attacker cannot abuse TCP-based services in the same manner, as TCP is connection-based and requires the attacker to complete a handshake. Hence, previous works only showed that the connection-less part of TCP can be exploited for DoS, e.g., by abusing middle boxes or handshakes for stateless reflection attacks. This work studies connection-based TCP amplification attacks. We first propose a methodology to explore the fundamentals of connection-based TCP amplification attacks-hosts with easily predictable sequence number selection algorithms. This allows attackers to complete IP-spoofed TCP handshakes, opening up the possibility of sending IP-spoofed application-layer (e.g., HTTP) requests to trigger amplified traffic. Our identification revealed over 160k vulnerable HTTP servers in the IPv4 space, out of which 54k servers host “amplifying” (≥ 1 kB large) resources. Using only ≤ 3 sequence number guesses, a single IP-spoofed HTTP request achieves an average amplification factor of 16.77 at an ≈ 80% success rate. Furthermore, we show that an attacker can also spoof cumulative ACKs and additional requests to further increase the impact of the amplification attack.
Yepeng Pan, Lars Richter, Christian Rossow
ACSAC1
2024 TCP Spoofing: Reliable Payload Transmission Past the Spoofed TCP Handshake
abstract
TCP spoofing—the attack to establish an IP-spoofed TCP connection by bruteforcing a 32-bit server-chosen initial sequence number (ISN)—has been known for decades. However, TCP spoofing has had limited impact in practice. One limiting factor is that attackers not only have to guess the ISN to complete the handshake but also have to model the server’s send window to reliably transmit subsequent payload segments. While known bruteforcing attacks include payloads during the handshake already, this cannot correctly model interactive TCP dialogs and is also prohibitively expensive (if not impossible) for larger payloads. Relying on the impracticality of TCP spoofing, several services still rely on the source IP address to make security-critical decisions, such as for firewalling, spam classification or network-based authentication in databases.We show that attackers cannot only establish spoofed TCP connections but also reliably send spoofed TCP payloads over these connections. We introduce two such sending primitives. First, we show how attackers can abuse the permissive handling of the TCP send window to inject payloads via efficient bruteforce attacks. Second, we introduce feedback-guided TCP spoofing that enables attackers to leak the server-chosen ISN. We introduce three feedback channels; one exploiting TCP SYN cookies and two leveraging operations specific to email and database applications. We find that such sending primitives can reliably transfer payload over spoofed connections and show their prevalence. We conclude with a discussion on countermeasures and our disclosure process.
Yepeng Pan, Christian Rossow
SP1
2024 Loopy Hell(ow): Infinite Traffic Loops at the Application Layer
Yepeng Pan, Anna Ascheman, Christian Rossow
USENIX Security Symposium1