惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

T
Tenable Blog
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
V
Vulnerabilities – Threatpost
G
GRAHAM CLULEY
Simon Willison's Weblog
Simon Willison's Weblog
C
CXSECURITY Database RSS Feed - CXSecurity.com
P
Privacy International News Feed
H
Heimdal Security Blog
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
S
Secure Thoughts
MyScale Blog
MyScale Blog
C
Cyber Attacks, Cyber Crime and Cyber Security
V
Visual Studio Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
L
LINUX DO - 最新话题
D
Darknet – Hacking Tools, Hacker News & Cyber Security
The Cloudflare Blog
美团技术团队
Recorded Future
Recorded Future
T
Tailwind CSS Blog
Latest news
Latest news
Security Archives - TechRepublic
Security Archives - TechRepublic
Security Latest
Security Latest
Know Your Adversary
Know Your Adversary
Cloudbric
Cloudbric
Schneier on Security
Schneier on Security
I
Intezer
L
LINUX DO - 热门话题
P
Palo Alto Networks Blog
云风的 BLOG
云风的 BLOG
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
Vercel News
Vercel News
Attack and Defense Labs
Attack and Defense Labs
人人都是产品经理
人人都是产品经理
L
LangChain Blog
爱范儿
爱范儿
博客园 - 三生石上(FineUI控件)
博客园 - 叶小钗
L
Lohrmann on Cybersecurity
S
SegmentFault 最新的问题
W
WeLiveSecurity
C
Cybersecurity and Infrastructure Security Agency CISA
S
Securelist
SecWiki News
SecWiki News
V2EX - 技术
V2EX - 技术
IT之家
IT之家
Cyberwarzone
Cyberwarzone
F
Full Disclosure
Spread Privacy
Spread Privacy
阮一峰的网络日志
阮一峰的网络日志

Cryptology ePrint Archive

Asynchronous Lagrange-Based Threshold FHE with Smaller Modulus Overhead Breaking ACDGV MinRank Gabidulin encryption schemes over matrix codes Icy-DVRF: A Distributed Verifiable Random Function based on FROST signatures Frobenius-UOV: A Very Efficient Multivariate Public Key Signature Scheme Revisiting Linear Subspace Trails in Poseidon A New Multiscalar Multiplication Method Resistant to Timing Attacks Device Binding for Anonymous Credentials on Legacy Phones Beyond Quadratic: Unlocking Pseudorandomness with Quartic Character Multi-leveled and ISA/IEC 62443-aware Certificate Transparency to Protect the PKI Service Supply Chain of Operational Technology rBFT: a Revamped Two-Stage BFT from Delegated Committee Delving Deep into Security Guarantees against Integral Distinguishers with Applications to PRESENT, TWINE and LBLOCK On the Communication Complexity of Sleepy Consensus Operationalising Post‑Quantum TLS: Automated Configuration Profiling and Hybrid PQC Deployment in Financial Infrastructure Enhancing Blockchain Proof of Stake with Active Weighted Signatures: The ADAPT Framework Threshold FHE with Short Decryption Shares without a Semi-trusted Server Efficient Bootstrapping in Fully Homomorphic Encryption for Matrix Arithmetic YsPIR: HE-Based Single-Server Private Information Retrieval with Low Communication Cost and High Throughput Black-box validation of Falcon key generation under numerical instability Tight Lattice-Based Signatures without Trapdoors from Search LWE Formalizing Blockchain PQC Signature Transition: How to Outpace Quantum Adversaries Optimized G+G Signature Storing Less in-the-Head: An Area-Efficient Hardware Architecture for SDitH-v2 SoK: Private LLM Inference using Approximate Homomorphic Encryption BitVM3: Efficient Bitcoin Bridges via Garbled Circuits Private Function Evaluation with Linear Complexity Obscura: Privacy-Preserving Protocol for the Algorand Blockchain Using LSAG Ring Signatures Cryptanalysis of Definite and Indefinite Lattice Isomorphism Problems With Applications to HAWK and DEFI Formalizing and Strengthening the Security Proof of NTOR Verifiable Anomaly and Similarity Detection Using Matrix Profile in Private Time-series Privacy Coins Under Viewing Key Compromise Adaptively-Secure Flexible and Identity-Based Broadcast Encryption from Decomposed LWE MERIDIAN: A Toroid-Inspired Permutation Block Cipher for Constrained Environments Toward Practical Fair Data Exchange: Eliminating In-Circuit Public-Key Operations Fault Injection Attacks Against zkSTARKs Beyond Binary: crosscorrelation of Cubic, Quartic and Quintic Character Sequences A Post-Quantum Accountable Sanitizable Signature Scheme Based on Unbalanced Oil and Vinegar Better Usability: Leakage-Resistant AEADs from Single-length Blockciphers TieredOMap: Skewness-Aware Oblivious Map Non-Adaptive Programmable PRFs and Applications to Stacked Garbling Mosaic: Practical Malicious Security for Garbled Circuits on Bitcoin Efficient Bootstrapping of Matrices in FHE Formal Verification, Integration and Physical Evaluation of Prime-Field Masking on Silicon New Techniques for Communication-Efficient Secure Comparison Protocols Verifying Provenance of Digital Media: Security Analysis of C2PA and its Implementation EQuADiSE: Efficient Quantum-safe Adaptive Distributed Symmetric-key Encryption Panther: Robust Hybrid KEM Combiners via Structural Splicing Cobra: All-in-one for full-fledged defense — a hybrid nested KEM SCOUT-CT: Sound Constant-Time Outcome with Uncertainty Tracking using multi-taint analysis Cryptanalysis of the Sharafi–Daghigh digital signature scheme Improved Garbled RAM via Garbled Merge A Simple Batched Threshold Encryption Scheme GlitchSnipe: Toward Localized Voltage Fault Attacks MCU: An Efficient and Scalable Nonlinear Function Evaluation in MPC without Preprocessing Divide-and-Pair: Faster subgroup membership testing for elliptic curves Related-Key Multi-Pair Neural Distinguishers: Analysis and Applications to Lightweight Block Ciphers MDSS-STAR: Private Heavy-Hitters through Multi-Dealer Secret Sharing How to Authenticate a Non-Deterministic Computation Quick Draw Queries: Lightweight Searchable Public-key Ciphertexts with Hidden Structures via Non-Interactive Key Exchange Boolean Arithmetic over $\mathbb{F}_2$ from Group Commutators Open Problems in List Decoding and Correlated Agreement An Efficient Identity-Based Blind Signature Scheme from SM9 Tighter Bounds for the Oblivious Bit-Fixing Inner Product Extractor on Biased Seeds Counting and recovering the quadratic relations of a vectorial function Perils of Parallelism: Transaction Fee Mechanisms under Execution Uncertainty RoKoko: Lattice-based Succinct Arguments, a Committed Refinement Aggregator-Based Voting using proof of Partition HARE: Compact HQC via Distance-Informed Erasure Decoding A Maliciously-Secure Post-Quantum OPRF from Crypto Dark Matter Byzantine Consensus in the Partially Authenticated Setting Post-Quantum Anonymous Signatures from the Lattice Isomorphism Group Action Issuer-Hiding for BBS Anonymous Credentials via Randomizable Keys Relaxed Modular PCS from Arbitrary PCS and Applications to SNARKs for Integers Cross-Algorithm Deep Learning-based Non-Profiled Side-Channel Attacks Exploiting Symmetric Leakage Key Recovery Attacks on UOV Using $p^\ell$-truncated Polynomial Rings Reducing the Number of Qubits in Quantum Discrete Logarithms on Elliptic Curves PhantomCrypt: Second-Order Deniable Encryption with Post-Quantum Security When Trying to Catch Cheaters Breaks the MPC: Breaking and Fixing Delayed Consistency Checks in Trident, Fantastic Four, SWIFT, and Quad (Full Version) On the Use of Atkin and Weber Modular Polynomials in Isogeny Proofs of Knowledge Minimizing Mempool Dependency in PoW Mining on Blockchain: A Paradigm Shift with Compressed Block Representation for Enhanced Scalability, Decentralization and Security. Beyond-Birthday-Bound Security with HCTR2: Cascaded Construction and Tweak-based Key Derivation Breaking the Myth of MPCitH Inefficiency: Optimizing MQOM for Embedded Platforms From Matrix to Polynomial NTRU FHE: Enabling Amortized Bootstrapping via Sparse Keys Adaptive NIKE for Unbounded Parties Hyperion: Private Token Sampling with Homomorphic Encryption TSS-PV: Traceable Secret Sharing with Public Verifiability A Graph-Theoretic Framework for Randomness Optimization in First-Order Masked Circuits Auntie: Unobservable Contracts from Zerocash and Trusted Execution Environments Fast Batch Matrix Multiplication in Ciphertexts Introducing GRAFHEN: GRoup-bAsed Fully Homomorphic Encryption without Noise Coppercloud: Blind Server-Supported RSA Signatures Threshold Public-Key Encryption: Definitions, Relations, and CPA-to-CCA Transforms On the $\gamma$-Spreadness of Average-Case to Worst-Case Transformations On the Regularity of the Generalized Birthday Problem The Pipes Model for Latency and Throughput Analysis Permutation-Based Hash from Non-Idealized Assumptions: Adding Feed-Forward to Sponge Secret-Key PIR from Random Linear Codes K-Linkable Ring Signatures and Applications in Generalized Voting Dynamic zk-SNARKs (with applications to sparse zk-SNARKs and IVC) ProxCode: Efficient Proximity Searchable Encryption from Error Correcting Codes DLFA: Deep Learning based Fault Analysis against Block Ciphers
Private IP Address Inference in NAT Networks via Off-Path TCP Control-Plane Attack
2026-01-30 · via Cryptology ePrint Archive

Paper 2026/149

Private IP Address Inference in NAT Networks via Off-Path TCP Control-Plane Attack

Adityavir Singh, Ashoka University

Mahabir Prasad Jhanwar, Ashoka University

Abstract

Recent work at NDSS 2024 demonstrated that widely deployed NAT behaviors in Wi-Fi routers – including port preservation, insufficient reverse path validation, and the absence of TCP window tracking enable off-path TCP hijacking attacks in NATed wireless networks. These attacks exploit design weaknesses in NAT gateway routers to detect whether some internal client behind the NAT maintains an active TCP connection with a target server and, upon detection, to disrupt or manipulate that connection. In this paper, we show that these behaviors have significantly broader privacy implications. We demonstrate that an off-path attacker can not only hijack active TCP connections but also accurately infer the private IP addresses of individual clients behind a NAT that are engaged in TCP communication with a target server. Our attack operates under the same realistic assumptions as prior work, yet leverages previously unexplored behaviors in NAT state management and TCP control-plane interactions to reconstruct the full client-side connection tuple. We evaluate our attack both in a controlled laboratory testbed and in a real-world Wi-Fi network. For SSH connections, our method reliably identifies the private IP addresses of connected clients and enables forcible termination of their TCP sessions. For HTTPS connections, although the attacker successfully terminates the underlying TCP connection, modern browsers rapidly re-establish a new connection using new ephemeral ports; nevertheless, our attack reveals the private IP addresses of the originating clients, exposing a persistent privacy leakage. Our findings demonstrate that off-path TCP hijacking attacks in NATed Wi-Fi networks pose a serious and previously unrecognized threat to client privacy, extending well beyond connection disruption to enable deanonymization of internal hosts.

BibTeX

@misc{cryptoeprint:2026/149,
      author = {Suraj Sharma and Adityavir Singh and Mahabir Prasad Jhanwar},
      title = {Private {IP} Address Inference in {NAT} Networks via Off-Path {TCP} Control-Plane Attack},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/149},
      year = {2026},
      url = {https://eprint.iacr.org/2026/149}
}