Network Address Translation (NAT) plays an essential role in shielding devices inside an internal local area network from direct malicious accesses from the public Internet. However, recent studies show the possibilities of penetrating NAT boxes in some specific circumstances. The penetrated NAT box can be exploited by attackers as a pivot to abuse the otherwise inaccessible internal network resources, leading to serious security consequences. In this paper, we aim to conduct an Internet-wide penetration testing on NAT boxes. The main difference between our study and the previous ones is that ours is based on the TCP/IP side channels. We explore the TCP/IP side channels in the research literature, and find that the shared-IPID side channel is the most suitable for NAT-penetration testing, as it satisfies the three requirements of our study: generality, ethics, and robustness. Based on this side channel, we develop an adaptive scanner that can accomplish the Internet-wide scanning in 5 days in a very non-aggressive manner. The evaluation shows that our scanner is effective in both the controlled network and the real network. Our measurement results reveal that more than 30,000 network middleboxes are potentially vulnerable to NAT penetration. They are distributed across 154 countries and 4,146 different organizations, showing that NAT-penetration poses a serious security threat.
翻译:网络地址转换(NAT)在保护内部局域网设备免受公共互联网直接恶意访问方面发挥着重要作用。然而,近年研究表明,在特定情况下存在穿透NAT设备的可能性。攻击者可利用已穿透的NAT设备作为跳板,滥用原本无法访问的内部网络资源,引发严重的安全后果。本文旨在对NAT设备开展全网穿透测试。与先前研究的主要区别在于,我们的研究基于TCP/IP侧信道。通过梳理相关文献中的TCP/IP侧信道技术,我们发现共享IPID侧信道最适合用于NAT穿透测试,因其同时满足本研究的三项要求:通用性、伦理性和鲁棒性。基于该侧信道,我们开发了一种自适应扫描器,能够在5天内以极低攻击性方式完成全网扫描。实验评估表明,该扫描器在受控网络和真实网络中均表现有效。测量结果显示,超过30,000个网络中间盒存在NAT穿透漏洞,这些设备分布在154个国家和4,146个不同组织中,表明NAT穿透已成为严重的安全威胁。