EIPSIM: Modeling Secure IP Address Allocation at Cloud Scale

10/26/2022
by   Eric Pauley, et al.
0

Public clouds provide impressive capability through resource sharing. However, recent works have shown that the reuse of IP addresses can allow adversaries to exploit the latent configurations left by previous tenants. In this work, we perform a comprehensive analysis of the effect of cloud IP address allocation on exploitation of latent configuration. We first develop a statistical model of cloud tenant behavior and latent configuration based on literature and deployed systems. Through these, we analyze IP allocation policies under existing and novel threat models. Our resulting framework, EIPSim, simulates our models in representative public cloud scenarios, evaluating adversarial objectives against pool policies. In response to our stronger proposed threat model, we also propose IP scan segmentation, an IP allocation policy that protects the IP pool against adversarial scanning even when an adversary is not limited by number of cloud tenants. Our evaluation shows that IP scan segmentation reduces latent configuration exploitability by 97.1 currently deployed by cloud providers. Finally, we evaluate our statistical assumptions by analyzing real allocation and configuration data, showing that results generalize to deployed cloud workloads. In this way, we show that principled analysis of cloud IP address allocation can lead to substantial security gains for tenants and their users.

READ FULL TEXT

page 1

page 7

research
04/11/2022

Measuring and Mitigating the Risk of IP Reuse on Public Clouds

Public clouds provide scalable and cost-efficient computing through reso...
research
06/19/2018

G-BAM: A Generalized Bandwidth Allocation Model for IP/MPLS/DS-TE Networks

Bandwidth Allocation Models (BAMs) configure and handle resource allocat...
research
02/04/2021

Privacy Preserving and Resilient RPKI

Resource Public Key Infrastructure (RPKI) is vital to the security of in...
research
08/23/2023

IP Neo-colonialism: Geo-auditing RIR Address Registrations

Allocation of the global IP address space is under the purview of IANA, ...
research
07/27/2018

An experiment in distributed Internet address management using blockchains

The current system to manage the global pool of IP addresses is centrali...
research
04/01/2022

Preventing Distillation-based Attacks on Neural Network IP

Neural networks (NNs) are already deployed in hardware today, becoming v...
research
08/16/2023

Evaluating IP Blacklists Effectiveness

IP blacklists are widely used to increase network security by preventing...

Please sign up or login with your details

Forgot password? Click here to reset