Что такое ip спуфинг и как предотвращать спуфинг-атаки

Содержание:

How PureVPN Can Help You Protect Against IP Spoofing Attacks

IP spoofing requires the attacker to be on the same network as you. More importantly, the attack needs some ideal conditions for it to be executed. For instance, packets must be unencrypted in order to execute an IP spoofing attack.

Here, a VPN such as PureVPN is your best bet as it can help you stay safe from the clutches of a spoof attack through its military-grade encryption.

When you connect to a VPN, your data is transmitted to the ISP through an encrypted tunnel. Everything that goes through the tunnel is protected with 256-bit encryption.

So, even if an attacker plans to spoof your IP packets, he won’t be able to do it without resolving the packets which won’t be possible due to end to end encryption.

OSI Layer Model

A key component to understanding how to actually spoof an IP address is one needs to have a vague understanding of the Open Source Interconnection 7 layer model. This is a model that describes how a computer takes a request from a web browser or some other application at the application layer and goes out, to the network to fetch the data and bring it back. It’s important to understand that approximately 98% of all active web development going on today takes place at the application layer or layer 7 of the OSI model. Your web browser, ftp client, mail client, or custom application all live at layer 7 in the model, for the most part and they’re all going to make a high level request over one protocol or another. In C#, typically they are used for making such high level requests.

The OSI layer model looks like this:

When a request for a web page such as my application (Web Browser) in this case packages that application up, and sends it on down to layer 6,5,4,3. Layers 4 & 3 are where the interesting things start to happen, that domain name is turned into an IP address, packets are formed, containing the type of packet, the destination IP and the source IP, so I can get the data back. My pay load (Http Get request) in this instance is addressed, control measures on the flow are put into place and the information is pushed down to layers 2 & 1 which are the low level network (out onto the internet) and the physical network (cables, switches, routers) and with any luck in not to much time, I’ll get some return information that will start to work its way back up the OSI stack containing my return payload which is the content you’re reading right now.

TCP/IP Stack

The good news for web application developers and most application developers that want to make web requests is that there is no need to really care what each and every layer of the OSI stack does and there is therefore a simplified version of the OSI model, commonly known as the TCP/IP stack.

The TCP/IP stack looks like this:

You can clearly see that the TCP/IP stack is just a simplified version of the world where the TCP/IP stack considers the first 3 layers of the OSI model to be the application layer, and the last 4 to be data control and flow.

To really understand this, and it’s critical that we do before proceeding any further, let’s consider a mapping of the TCP/IP stack to the OSI 7 layers.

Looking at these 3 different views of the networking world, it should be apparent that if we make a high level request for a resource, it’s really too late to try to enforce any kind of spoofing once I’ve asked for that high level request to be sent. The reason is, once I send a high level request, libraries, other applications and drivers take over at lower 4 levels of the TCP/IP stack and figure out all the hard work for me, and I am left with little chance to jump in and try and influence the process. A high level request interacts with the high levels of the stacks and doesn’t leave me much of a chance to mess with anything.

GPS-Spoofing

Spoofing-атака на GPS — атака, которая пытается обмануть GPS-приемник, широковещательно передавая немного более мощный сигнал, чем полученный от спутников GPS, такой, чтобы быть похожим на ряд нормальных сигналов GPS. Эти имитирующие сигналы изменены таким способом, чтобы заставить получателя неверно определять своё местоположение, считая его таким, какое отправит атакующий. Поскольку системы GPS работают, измеряя время, которое требуется для сигнала, чтобы дойти от спутника до получателя, успешный спуфинг требует, чтобы атакующий точно знал, где его цель — так, чтобы имитирующий сигнал мог быть структурирован с надлежащими задержками сигнала.

Атака спуфинга GPS начинается, широковещательно передавая немного более мощный сигнал, который указывает корректную позицию, и затем медленно отклоняется далеко к позиции, заданной атакующим, потому что слишком быстрое перемещение повлечет за собой потерю сигнальной блокировки, и в этой точке spoofer станет работать только как передатчик помех. Одна из версий захвата американского беспилотника Lockheed RQ 170 в северо-восточном Иране в декабре 2011 — это результат такой атаки. Spoofing GPS был предсказан и обсужден в сообществе GPS ранее, но никакой известный пример такой вредоносной атаки спуфинга ещё не был подтвержден.

29 июля 2013 студентам из университета Остина, Техас, удалось отклонить от курса 213-футовую яхту с помощью метода GPS-спуфинга.

В ноябре 2016 появилась информация о том, что Федеральная служба охраны использует оборудование, имитирующее сигналы спутника GPS на частоте L1. Действительная локация подменяется координатами аэропорта «Внуково», что, вероятно, связано с опасениями использования гражданских дронов вблизи правительственных зданий. В 2019 году общественные организации показали активное использование спуфинга Федеральной службой охраны при поездках VIP и в зонах военных действий.

Spoofing голосовой почты

Технология спуфинга позволяет кому-либо сделать так, что вызываемый абонент будет считать, что ему звонит ваш телефон, в то время как на самом деле это звонит мошенник. Использование этой технологии в недобросовестных целей является незаконным.

В целях предотвращения несанкционированного доступа к голосовой почте в целях мошеннической деятельности, таких как подмена ID звонящего, вы должны использовать голосовую почту защищенную сильным паролем, устанавливаемым при настройке учетной записи. В противном случае, сообщения вашей голосовой почты могут быть уязвимы для несанкционированного доступа с помощью спуфинга.

Как вы можете защитить себя?

Существует несколько способов защитить себя от IP-спуфинга, но многие из них являются высокотехнологическими методами, и используются главным образом веб-администраторами. Однако есть несколько инструментов, которые могут защитить вас от любой атаки IP-спуфинга.

VPN

Зашифровывая трафик, VPN не дает хакерам возможности получить доступ к вашим данным и как-то участвовать в процессе. Например, функция CyberSec от NordVPN может защитить вас от вредоносных или взломанных сайтов, которые могут которые могут передать вам ложные пакеты данных.

Антивирусная программа

Антивирусное ПО поможет вам, если кому-то удастся обмануть вас. Мощная антивирусная программа сканирует входящие пакеты данных, чтобы узнать, содержат ли они вредоносный код. Это не полная защита, но антивирус хорошо иметь в любом случае!

IP address spoofing in application layer attacks

For application layer connections to be established, the host and visitor are required to engage in a process of mutual verification, known as a TCP three-way handshake.

The process consists of the following exchange of synchronization (SYN) and acknowledgement (ACK) packets:

  1. Visitor sends a SYN packet to a host.
  2. Host replies with a SYN-ACK.
  3. Visitor acknowledges receipt of the SYN-ACK by replying with an ACK packet.

Source IP spoofing makes the third step of this process impossible, as it prohibits the visitor from ever receiving the SYN-ACK reply, which is sent to the spoofed IP address.

Since all application layer attacks rely on TCP connections and the closure of the 3-way handshake loop, only network layer DDoS attacks can use spoofed addresses.

Что такое IP-адрес и IP-спуфинг

IP-адрес является уникальным сетевым адресом узла в компьютерной сети, которая сформирована на базе объединения протоколов TCP и IP. Интернет-сеть требует, чтобы каждый адрес был уникальным, а также в рамках локальной сети должен поддерживаться тоже уникальный адрес.

Структура IP-адреса представляет собой два элемента – номер сети и номер узла.

IP-спуфинг определяется как одно из направлений хакерских атак, когда задействуется чужой IP, чтобы обмануть систему безопасности и проникнуть в постороннюю компьютерную сеть. Слово «spoof» с английской языка означает мистификацию, то есть злоумышленник маскируется под своего, чтобы проникнуть к частным данным.

Метод спуфинга используется в определенных целевых атаках, когда хакер изменяет данные адреса отправителя в IP-пакете. Все эти действия позволяют скрыть истинный адрес того, кто совершает данную атаку, чтобы получить ответный пакет на свой адрес или же реализовать другие личные цели.

Чаще всего онлайн-нарушители атакуют чужие компьютеры, чтобы фальсифицировать собственные заголовки IP-пакетов, в частности изменять IP-адрес источника. В этом случае спуфинг приравнивается к «слепой подмене». На самом деле, фальсифицированный пакет не может передаться в машину крэкера из-за измененного исходящего адреса. Но есть способы обхода и получения желаемого.

Таких способов два:

  • Source routing или маршрутизация от источника – в протоколе IP можно задать нужный маршрут для передачи пакета данных;
  • Re-routing или перемаршрутизация – при использовании протокола RIP можно сделать замену и предложить свой RIP-пакет с измененными данными.

IP Address spoofing in DDoS attacks

IP address spoofing is used for two reasons in DDoS attacks: to mask botnet device locations and to stage a reflected assault.

Masking botnet devices

A botnet is a cluster of malware-infected devices remotely controlled by perpetrators without the knowledge of their owners. They can be instructed to collectively access a given domain or server, providing perpetrators with the computing and networking resources to generate huge traffic floods. Such floods enable botnet operators, (a.k.a. shepherds), to max out their target’s resource capacity, resulting in server downtime and network saturation.

Botnets are typically comprised of either random, geographically dispersed devices, or computers belonging to the same compromised network (e.g., hacked hosting platform).

By using spoofed IP addresses to mask the true identities of their botnet devices, perpetrators aim to:

  1. Avoid discovery and implication by law enforcement and forensic cyber-investigators.
  2. Prevent targets from notifying device owners about an attack in which they are unwittingly participating.
  3. Bypass security scripts, devices and services that attempt to mitigate DDoS attacks through the blacklisting of attacking IP addresses.

Reflected DDoS

A reflected DDoS attack uses IP spoofing to generate fake requests, ostensibly on behalf of a target, to elicit responses from under protected intermediary servers. The perpetrator’s goal is to amplify their traffic output by triggering large responses from much smaller requests.

Common reflected DDoS attack methods include:

  • DNS amplification – An ANY query originating from a target’s spoofed address is sent to numerous unsecured DNS resolvers. Each 60 byte request can prompt a 4000 byte response, enabling attackers to magnify traffic output by as much as 1:70.
  • Smurf attack – An ICMP Echo request is sent from a target’s spoofed address to an intermediate broadcast network, triggering replies from every device on that network. The degree of amplification is based on the number of devices to which the request is broadcast. For example, a network with 50 connected hosts results in a 1:50 amplification.
  • NTP amplification – A get monlist request, containing a target’s spoofed IP address, is sent to an unsecure NTP server. As in DNS amplification, a small request triggers a much larger response, allowing a maximum amplification ratio of 1:200.

Applications

IP address spoofing involving the use of a trusted IP address can be used by network intruders to overcome network security measures, such as authentication based on IP addresses. This type of attack is most effective where trust relationships exist between machines. For example, it is common on some corporate networks to have internal systems trust each other, so that users can log in without a username or password provided they are connecting from another machine on the internal network – which would require them already being logged in. By spoofing a connection from a trusted machine, an attacker on the same network may be able to access the target machine without authentication.

IP address spoofing is most frequently used in denial-of-service attacks, where the objective is to flood the target with an overwhelming volume of traffic, and the attacker does not care about receiving responses to the attack packets. Packets with spoofed IP addresses are more difficult to filter since each spoofed packet appears to come from a different address, and they hide the true source of the attack. Denial of service attacks that use spoofing typically randomly choose addresses from the entire IP address space, though more sophisticated spoofing mechanisms might avoid non routable addresses or unused portions of the IP address space. The proliferation of large botnets makes spoofing less important in denial of service attacks, but attackers typically have spoofing available as a tool, if they want to use it, so defenses against denial-of-service attacks that rely on the validity of the source IP address in attack packets might have trouble with spoofed packets. , a technique used to observe denial-of-service attack activity in the Internet, relies on attackers’ use of IP spoofing for its effectiveness.

Почему IP-спуфинг опасен?

Хакеры придумали бесчисленное множество способов использования вредоносных программ для атаки отдельных пользователей, серверов и даже приложений. Вот три наиболее распространенных вредоносных использования IP-спуфинга:

Распространение вирусов

Если злоумышленник может обмануть компьютер, показывая ему, что файлы находятся на конкретном веб-сайте, он может отправить вам все, что угодно. Это означает, что IP-spoofing может использоваться для замены содержимого, которое вы действительно хотите скачать, на вредоносное ПО и вирусы.

DDoS-атаки

При DDoS-атаке сервер или веб-сайт забрасываются огромным количеством мошеннических запросов. Часто эти запросы производятся устройствами, зараженными червями-ботнетами, владельцы которых даже не знают, что они являются частью армии хакера. Однако IP-спуфинг также может использоваться для перенаправления сообщений. Хакер может отправлять миллионы запросов на файлы и менять IP-адрес, чтобы все серверы отправляли ответы на устройство жертвы.

Атаки «Человек-посредине»

Это тип атаки «Man-in-the-middle», — когда хакер находится как бы между пользователем и сервером. Такие атаки чаще всего встречаются в местах с незащищенным Wi-Fi, например, в кафе и аэропортах. Если вы подключились к небезопасному HTTP-адресу, хакер может использовать IP-спуфинг, чтобы притворяться одновременно и пользователем, и сервером, тем самым обманывая обе стороны и получая доступ к сообщениям.

Защита от IP-спуфинга[править | править код]

Простейший способ проверить, что подозрительный пакет пришёл от верного отправителя — отправить пакет на IP отправителя. Обычно для IP-спуфинга используется случайный IP, и вполне вероятно, что ответ не придёт. Если же придёт, имеет смысл сравнить поле TTL (Time to live) полученных пакетов. Если поля не совпадают — пакеты пришли из разных источников.

На сетевом уровне атака частично предотвращается с помощью фильтра пакетов на шлюзе. Он должен быть настроен таким образом, чтобы не пропускать пакеты, пришедшие через те сетевые интерфейсы, откуда они прийти не могли. Например, фильтрация пакетов из внешней сети с исходным адресом внутри сети.

Одним из самых надёжных методов защиты от подмены IP-адреса является сопоставление MAC-адреса (Ethernet ) и IP-адреса ( протокола IP) отправителя. Например, если пакет с IP адресом из внутренней сети имеет MAC адрес шлюза — этот пакет стоит отбросить. В современных сетевых устройствах изменение MAC-адреса (физического адреса) не является проблемным.

Как защититься от спуфинг-атаки

Но пользователь никогда не узнает о том, что его атаковали, поскольку может не обратить внимание на изменение поведения сайтов или появления подозрительных деталей. Но если вы засомневаетесь в надежности веб-ресурса, лучше сразу закрыть его или не выполнять никакие действия, особенно финансовые операции, чтобы обезопасить себя от взлома и проникновения мошенников

Специфика спуфинга в том, что такая атака маскирует истинный источник, поэтому его не легко устранить. Зато соблюдение элементарных правил безопасности позволит защититься или, как минимум, предотвратить попытку проникновения к пользовательским данным.

IP спуфинг нельзя остановить, но важно принять эффективные меры, чтобы не дать поддельным пакетам попасть в сеть. В этом случае используется прием фильтрации входа

Данная мера заключается в том, что используется опция фильтра, чтобы проверять входящие IP-пакеты и изучать их исходные заголовки. Если выявляется несовпадение данных или же возникает подозрение в их подлинности, они будут отклонены.

Многие сети практикуют фильтрацию исходящего типа, чтобы проверять направляемые другим машинам пакеты с данными. Это также помогает предотвращать попытки взломов и ip спуфинг-атак.

Пользователям рекомендуется применять такие меры защиты и предотвращения действий злоумышленников:

  • не отвечать на сообщения, в которых указывается предоставить свои личные данные;
  • всегда внимательно изучать адрес отправителя;
  • замечать странности в поведении сайтов или прекращать пользоваться ими, если сомневаетесь в надежности ресурса.

Background

The basic protocol for sending data over the Internet network and many other computer networks is the Internet Protocol (IP). The protocol specifies that each IP packet must have a header which contains (among other things) the IP address of the sender of the packet. The source IP address is normally the address that the packet was sent from, but the sender’s address in the header can be altered, so that to the recipient it appears that the packet came from another source.

The protocol requires the receiving computer to send back a response to the source IP address, so that spoofing is mainly used when the sender can anticipate the network response or does not care about the response.

The source IP address provides only limited information about the sender. It may provide general information on the region, city and town when on the packet was sent. It does not provide information on the identity of the sender or the computer being used.

IP address spoofing in security research

In security research, IP data derived from network layer assaults is often used to identify the country of origin of attacker resources. IP address spoofing, however, makes this data unreliable, as both the IP address and geolocation of malicious traffic is masked.

When reading reports relying solely on network IP data, it’s necessary to be aware of these limitations. For example, a report by a mitigation provider that doesn’t protect against application layer attacks can’t be relied on to provide accurate locations of botnet devices.

As a result, any substantial research into botnet countries of origin can only be based on application layer attack data.

See how Imperva DDoS Protection can help you with IP spoofing.

Request Demo
or learn more

About the Author

CdnSecurityEngineer

Engineer

Canada

I am a Sr Engineer for a major security firm; I have been developing software professionally for 8 years now; I’ve worked for start ups, small companies, large companies, myself, education. Currently the company I work for has 7,000+ employees worldwide. I am responsible for our platform security, I write code, implement features, educate other engineers about security, I perform security reviews, threat modeling, continue to educate myself on the latest software. By night, I actively work to educate other developers about security and security issues. I also founded a local chapter of OWASP which I organize and run.
I cut my teeth developing in C++ and it’s still where my heart is with development, lately I’ve been writing a lot of C# code & some java, but I do have a project or two coming out in C++ /DiectX 11 whenever I get the time.
When I am not developing code I am spending my time with my wife and daughter or I am lost deep in the woods some where on a camping trip with friends. If you can’t find me with a GPS and a SPOT device then chances are I am on the Rugby pitch playing Rugby and having a great time doing so.
You can find more about me and My thoughts on security

Steps to Avoid Spoofing

Most of the strategies used to avoid IP spoofing must be developed and deployed by IT specialists. The options to protect against IP spoofing include monitoring networks for atypical activity, deploying packet filtering to detect inconsistencies (like outgoing packets with source IP addresses that don’t match those on the organization’s network), using robust verification methods (even among networked computers), authenticating all IP addresses, and using a network attack blocker. Placing at least a portion of computing resources behind a firewall is also a good idea.

Web designers are encouraged to migrate sites to IPv6, the newest Internet Protocol. It makes IP spoofing harder by including encryption and authentication steps. Most of the world’s internet traffic still uses the previous protocol, IPv4. The Seattle Internet Exchange (one of two in the world showing IPv6 traffic statistics) indicates that only about 11 percent of traffic has migrated to the newer, more secure protocol as of mid-November 2017.

For end users, detecting IP spoofing is virtually impossible. They can minimize the risk of other types of spoofing, however, by using secure encryption protocols like HTTPS — and only surfing sites that also use them.

Related Articles:

Defense against spoofing attacks

Packet filtering is one defense against IP spoofing attacks. The gateway to a network usually performs ingress filtering, which is blocking of packets from outside the network with a source address inside the network. This prevents an outside attacker spoofing the address of an internal machine. Ideally the gateway would also perform egress filtering on outgoing packets, which is blocking of packets from inside the network with a source address that is not inside. This prevents an attacker within the network performing filtering from launching IP spoofing attacks against external machines. Intrusion Detection System (IDS) is a common use of packet filtering, which has been used to secure the environments for sharing data over network and host based IDS approaches.

It is also recommended to design network protocols and services so that they do not rely on the source IP address for authentication.

Upper layers

Some upper layer protocols provide their own defense against IP spoofing attacks. For example, Transmission Control Protocol (TCP) uses sequence numbers negotiated with the remote machine to ensure that arriving packets are part of an established connection. Since the attacker normally cannot see any reply packets, the sequence number must be guessed in order to hijack the connection. The poor implementation in many older operating systems and network devices, however, means that TCP sequence numbers can be predicted.

Spoofing definition

Spoofing is an impersonation of a user, device or client on the Internet. It’s often used during a cyberattack to disguise the source of attack traffic.

The most common forms of spoofing are:

  • DNS server spoofing – Modifies a DNS server in order to redirect a domain name to a different IP address. It’s typically used to spread viruses.
  • ARP spoofing – Links a perpetrator’s MAC address to a legitimate IP address through spoofed ARP messages. It’s typically used in denial of service (DoS) and man-in-the-middle assaults.
  • IP address spoofing – Disguises an attacker’s origin IP. It’s typically used in DoS assaults.

Spoofing звонящего

В телефонных сетях общего пользования можно узнать, кто вам звонит, глядя на информацию о вызывающем абоненте, которая передается с вызовом. Есть технологии, которые передают эту информацию на стационарные телефоны, на мобильные телефоны, а также с VoIP. В настоящее время появились технологии (особенно связанные с VoIP), которые позволяют абонентам передавать ложный идентификатор и представлять ложные имена и номера, которые, конечно, могут быть использованы в недобросовестных целях. Эти ложные идентификаторы вызывающего абонента могут быть переданы на любой телефон на планете, что делает всю информацию Caller ID теперь неактуальной. Благодаря распределенной географической природе Интернета, VoIP звонки могут быть сделаны в стране, отличной от приемника, что влечет за собой трудности работы какой-то правовой основы для контроля тех, кто будет использовать фальшивые удостоверения личности при звонках в недобросовестных целях.

Spoofing E-mail-адреса

Информацию об отправителе, показанную в электронной почте (поле «От»), можно легко подделать. Этот метод обычно используется спамерами, чтобы скрыть происхождение своей электронной почты и приводит к таким проблемам, как возвращенные письма (то есть спама в электронной почте обратного рассеивания).

В спуфинге подмену адреса электронной почты выполняют вполне тот же путь, как запись подделанного обратного адреса, используя обычную почту. Пока буква соответствует протоколу (то есть штамп, индекс), протокол SMTP отправит сообщение. Это может быть сделано через использование почтового сервера с telnet.

Применение атаки

Протокол транспортного (4) уровня TCP имеет встроенный механизм для предотвращения спуфинга — так называемые номера последовательности и подтверждения (sequence number, acknowledgement number). Протокол UDP не имеет такого механизма, следовательно, построенные на его основе приложения более уязвимы для спуфинга.

Рассмотрим установку соединения протокола TCP ():

  1. клиент отправляет TCP-пакет с установленным флагом , также он выбирает ISNc (Initial Sequence Number клиента, ).
  2. сервер увеличивает на единицу ISNc и отправляет его обратно вместе со своим ISNs (Initial Sequence Number сервера, ), а также флагами .
  3. клиент отвечает пакетом , содержащим ISNs, увеличенный на единицу.

Применяя IP-spoofing, крэкер не сможет увидеть ISNs, так как ответ от сервера ему не придёт. ISNs ему нужен на третьем шаге, когда он должен будет увеличить его на 1 и отправить. Чтобы установить соединение от имени чужого IP, атакующий должен угадать ISNs.
В старых операционных системах (ОС) было очень легко угадать ISN — он увеличивался на единицу с каждым соединением. Современные ОС используют механизм, который предотвращает угадывание ISN. Современные сервисы используют для аутентификации имя пользователя и пароль и передают данные в зашифрованном виде.

DNS усиление

Другая разновидность DoS-атаки. Атакующий компьютер посылает запросы на DNS-сервер, указывая в передаваемом пакете, в поле IP-адрес источника, IP-адрес атакуемого компьютера. Ответ DNS-сервера превышает объём запроса в несколько десятков раз, что усиливает вероятность успешной DoS-атаки.

TCP hijacking

Единственными идентификаторами, по которым конечный хост может различать TCP-абонентов и TCP-соединения, являются поля Sequence Number и Acknowledge Number. Зная эти поля и используя подмену IP адреса источника пакета на IP-адрес одного из абонентов, атакующий может вставить любые данные, которые приведут к разрыву соединения, к состоянию ошибки, либо же будут выполнять какую-либо функцию во благо атакующего. Жертва может даже не заметить этих манипуляций.

Заключение

С одной стороны, понимать спуфинг, что это атака хакеров – мало

Важно еще применять меры безопасности для защиты своих личных данных. Всегда пользуйтесь антивирусной программой, храните все важные файлы в надежно месте

IP-Spoofing является достаточно распространенной проблемой, и так легко от нее не избавиться. Если понимать, как все устроено и как действует, тогда проще обезопаситься, используя VPN сервисы, которые шифруют Ваш трафик, и совершать только проверенные манипуляции в сети.

Чтобы ваши личные данные всегда были в безопасности — используйте RusVPN на всех устройствах уже сейчас!

RusVPN для

Оценка 8.4 из 10

по рейтингу VPNBase

Получить

Добавить комментарий

Ваш адрес email не будет опубликован. Обязательные поля помечены *