Port Forwarding Services Are Forwarding Security Risks

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Wang, Haoyuan, Xue, Yue, Feng, Xuan, Zhou, Chao, Mi, Xianghang
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866916199277789184
author Wang, Haoyuan
Xue, Yue
Feng, Xuan
Zhou, Chao
Mi, Xianghang
author_facet Wang, Haoyuan
Xue, Yue
Feng, Xuan
Zhou, Chao
Mi, Xianghang
contents We conduct the first comprehensive security study on representative port forwarding services (PFS), which emerge in recent years and make the web services deployed in internal networks available on the Internet along with better usability but less complexity compared to traditional techniques (e.g., NAT traversal techniques). Our study is made possible through a set of novel methodologies, which are designed to uncover the technical mechanisms of PFS, experiment attack scenarios for PFS protocols, automatically discover and snapshot port-forwarded websites (PFWs) at scale, and classify PFWs into well-observed categories. Leveraging these methodologies, we have observed the widespread adoption of PFS with millions of PFWs distributed across tens of thousands of ISPs worldwide. Furthermore, 32.31% PFWs have been classified into website categories that serve access to critical data or infrastructure, such as, web consoles for industrial control systems, IoT controllers, code repositories, and office automation systems. And 18.57% PFWs didn't enforce any access control for external visitors. Also identified are two types of attacks inherent in the protocols of Oray (one well-adopted PFS provider), and the notable abuse of PFSes by malicious actors in activities such as malware distribution, botnet operation and phishing.
format Preprint
id arxiv_https___arxiv_org_abs_2403_16060
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Port Forwarding Services Are Forwarding Security Risks
Wang, Haoyuan
Xue, Yue
Feng, Xuan
Zhou, Chao
Mi, Xianghang
Cryptography and Security
We conduct the first comprehensive security study on representative port forwarding services (PFS), which emerge in recent years and make the web services deployed in internal networks available on the Internet along with better usability but less complexity compared to traditional techniques (e.g., NAT traversal techniques). Our study is made possible through a set of novel methodologies, which are designed to uncover the technical mechanisms of PFS, experiment attack scenarios for PFS protocols, automatically discover and snapshot port-forwarded websites (PFWs) at scale, and classify PFWs into well-observed categories. Leveraging these methodologies, we have observed the widespread adoption of PFS with millions of PFWs distributed across tens of thousands of ISPs worldwide. Furthermore, 32.31% PFWs have been classified into website categories that serve access to critical data or infrastructure, such as, web consoles for industrial control systems, IoT controllers, code repositories, and office automation systems. And 18.57% PFWs didn't enforce any access control for external visitors. Also identified are two types of attacks inherent in the protocols of Oray (one well-adopted PFS provider), and the notable abuse of PFSes by malicious actors in activities such as malware distribution, botnet operation and phishing.
title Port Forwarding Services Are Forwarding Security Risks
topic Cryptography and Security
url https://arxiv.org/abs/2403.16060