Keynote Speaker: Anat Bremler-Barr
Blavatnik School of Computer Science and AI, Tel Aviv University
Logical Vulnerabilities: The Blind Spots of Network Protocol Design
Abstract
In this talk, we will explore logical vulnerabilities and their root weaknesses. We will cover several of our recently discovered vulnerabilities, starting with the MadeYouReset attack, a novel Denial of Service (DoS) attack on HTTP/2 servers. We will demonstrate that the underlying logic of the notorious Rapid Reset attack, which was actively exploited as a zero-day vulnerability, was never fully understood, ultimately leaving the door open to the MadeYouReset vulnerability.
Next, we will showcase newly discovered logical vulnerabilities in DNS, specifically focusing on the CacheFlush attack, which triggers a DDoS attack by flushing the resolver cache. We will show how this logical weakness can be weaponized to create a side-channel attack on DNS forwarders. Finally, we will conclude by discussing the key lessons these logical vulnerabilities teach us about designing secure network protocols. The work covered in this talk was conducted in collaboration with Yehuda Afek, Gal Bar-Nachum, Shoham Danino, Yaniv Harel, Amit Klein, Gilad Moav, and Yuval Shavitt.
Bio
Prof. Anat Bremler-Barr is a Full Professor at the Blavatnik School of Computer Science and AI at Tel Aviv University. Her current research focuses on DNS security, cloud security, IoT security, DDoS mitigation, and CVE analysis. In 2001, she co-founded Riverhead Networks Inc., a company providing systems to protect against Denial-of-Service attacks, which was acquired by Cisco Systems in 2004. In 2010, she was awarded a prestigious European Research Council (ERC) Starting Grant for her research into Deep Packet Inspection of Next-Generation Network Devices. She is the founder and director of the Deepness Lab, which focuses on designing reliable and efficient networks and network devices.


