P4Control: Line-Rate Cross-Host Attack Prevention via In-Network Information Flow Control Enabled by Programmable Switches and eBPF

Osama Bajaber, Bo Ji, Peng Gao

IEEE Symposium on Security and Privacy 2024 · Day 3 · Continental Ballroom 5

Overview

In an era of sophisticated cyber threats, lateral movement has emerged as a pervasive technique allowing attackers to navigate compromised networks, escalating privileges and accessing sensitive data. The talk "P4Control: Line-Rate Cross-Host Attack Prevention via In-Network Information Flow Control Enabled by Programmable Switches and eBPF" introduces a novel defense mechanism designed to combat these multi-stage attacks in real-time. Presented by Osama Bajaber from Virginia Tech, this work, a collaboration with advisors Dr. Bo Ji and Dr. Peng Gao, addresses the critical gap in current security solutions: the lack of end-to-end visibility across both host and network layers.

Watch on YouTube

Visual summary for P4Control: Line-Rate Cross-Host Attack Prevention via In-Network Information Flow Control Enabled by Programmable Switches and eBPF by Osama Bajaber, Bo Ji, Peng Gao
Visual summary for P4Control: Line-Rate Cross-Host Attack Prevention via In-Network Information Flow Control Enabled by Programmable Switches and eBPF by Osama Bajaber, Bo Ji, Peng Gao

Key moments

  1. 0:00 Introduction to cross-host attacks and lateral movement problem
  2. 0:40 Detailed example of a cross-host lateral movement attack
  3. 2:20 Root cause: limitations of current network and host defenses
  4. 3:30 Explanation of Information Flow Control (IFC) and DFC
  5. 4:55 P4Control's key contribution: In-network DFC using programmable switches
  6. 5:05 Demonstration: How DFC labels propagate across hosts and network
  7. 6:00 P4Control's threat model and challenges for end-to-end visibility

P4Control: Line-Rate Cross-Host Attack Prevention via In-Network Information Flow Control Enabled by Programmable Switches and eBPF

Speakers: Osama Bajaber, PhD Student, Virginia Tech; Bo Ji, Advisor, Virginia Tech; Peng Gao, Advisor, Virginia Tech

Conference: IEEE S&P

YouTube: https://www.youtube.com/watch?v=5Q4pIojkLy4

Overview

In an era of sophisticated cyber threats, lateral movement has emerged as a pervasive technique allowing attackers to navigate compromised networks, escalating privileges and accessing sensitive data. The talk "P4Control: Line-Rate Cross-Host Attack Prevention via In-Network Information Flow Control Enabled by Programmable Switches and eBPF" introduces a novel defense mechanism designed to combat these multi-stage attacks in real-time. Presented by Osama Bajaber from Virginia Tech, this work, a collaboration with advisors Dr. Bo Ji and Dr. Peng Gao, addresses the critical gap in current security solutions: the lack of end-to-end visibility across both host and network layers.

P4Control tackles this challenge by extending the concept of Decentralized Information Flow Control (DFC) from individual hosts into the network fabric itself. By leveraging the power of programmable switches and eBPF technology, the system ensures that security labels, representing data sensitivity and integrity, are propagated with network traffic and enforced at line rate. This innovative approach not only provides unprecedented visibility into information flows but also enables immediate policy enforcement, effectively neutralizing cross-host attacks before they can inflict significant damage. The solution is particularly relevant in the context of evolving Zero Trust Architecture mandates, offering a foundational technology to precisely control and verify requests within complex enterprise environments.

Background

▶ Watch: Introduction to cross-host attacks and lateral movement problem (0:00)

The modern threat landscape is characterized by persistent and adaptive adversaries who frequently employ lateral movement to achieve their objectives. Incidents like the Miter breach highlight how attackers exploit initial compromises to move between intermediate hosts, deepening their access and bypassing traditional perimeter defenses. This allows them to exfiltrate confidential data, spread malware, or gain unauthorized access to critical resources. The core problem enabling these attacks is a fundamental lack of end-to-end information flow visibility across an organization's IT infrastructure.

Existing security solutions often fall short in addressing this nuanced threat. Network-level defenses, such as firewalls and Network Intrusion Detection Systems (NIDS), operate primarily on network headers and traffic patterns. They lack insight into the internal activities of hosts, making them ineffective against attacks that leverage legitimate internal connections or pivot through compromised machines. Consequently, their effectiveness is limited to blocking direct network accesses. Conversely, host-level defenses, including Host Intrusion Detection Systems (HIDS) and antivirus software, are typically confined to monitoring activities within a single host. While some advanced solutions utilize provenance graphs to stitch together host and network logs, these often function in a forensic analysis setting, detecting attacks only after they have occurred and damage has already been done. There is a pressing need for a proactive, real-time defense that can correlate and enforce security decisions across the entire attack chain.

Information Flow Control (IFC) is a security mechanism designed to track and regulate how information moves within a system. Early IFC models relied on a centralized authority or reference monitor to assign labels (e.g., "top secret," "public") to data and control its access. While effective in highly controlled environments like military systems, this centralized approach proved too rigid and limited for broader enterprise adoption. To overcome this, Decentralized Information Flow Control (DFC) emerged, empowering data owners to define their own policies and labels. DFC labels typically consist of a set of tags, which can represent security levels, user groups, or compartments. DFC also introduces mechanisms for declassification (removing secrecy tags to allow broader access) and endorsement (adding integrity tags to certify data origin or trustworthiness). Despite these advancements, a major limitation of current DFC implementations is their confinement to the host level, lacking any extended visibility or enforcement capabilities at the network layer. This critical gap leaves systems vulnerable to sophisticated cross-host attacks that exploit the blind spots between host and network security contexts.

Key Findings

▶ Watch: Root cause: limitations of current network and host defenses (2:20)

P4Control introduces several key findings and contributions that fundamentally alter how cross-host attacks can be prevented:

  • In-Network DFC Enforcement: The core contribution is the realization of an in-network DFC mechanism that extends information flow control from individual processes within hosts to network packets themselves. This is achieved by propagating DFC labels along with system activities and network communications, following safe message rules to ensure both secrecy and integrity.
  • Programmable Data Plane as a Security Enforcer: P4Control demonstrates that programmable switches, specifically those supporting P4 language, can be effectively transformed into line-rate security enforcement points. By defining custom packet processing logic and header formats, these switches can identify, verify, and enforce DFC policies on network traffic without introducing significant latency.
  • eBPF for Transparent Host Integration: The research highlights eBPF (extended Berkeley Packet Filter) as a crucial enabler for transparently integrating host-level DFC agents. eBPF allows for extending kernel capabilities and monitoring system calls without modifying the kernel source code, ensuring lightweight and compatible DFC context propagation from processes to network packets.
  • Real-Time, Line-Rate Attack Prevention: P4Control proves the feasibility of preventing cross-host attacks in real-time and at network line rate. This contrasts sharply with traditional forensic analysis approaches, providing an immediate defense mechanism against lateral movement and unauthorized information flows.
  • NetCL for Policy Abstraction: The introduction of Network Control Language (NetCL) is a significant finding, demonstrating how complex, low-level programmable switch configurations can be abstracted into an expressive, easy-to-use policy language. NetCL empowers network administrators to define sophisticated secrecy and integrity policies, including declassification and endorsement rules, and dynamically update them.

Technical Deep Dive

▶ Watch: Explanation of Information Flow Control (IFC) and DFC (3:30)

P4Control's architecture addresses the complexities of achieving end-to-end information flow visibility and real-time enforcement against sophisticated cross-host attacks. The threat model P4Control aims to counter involves attackers leveraging multiple intermediate victims to evade network defenses, seeking to access unauthorized resources, exfiltrate confidential data, or spread malware, originating from both internal and external network points.

To achieve its goals, P4Control tackles several core challenges:

  1. End-to-End Information Flow Visibility: This necessitates extending DFC context beyond host boundaries into the network level.
  2. Granular Authorization: A robust category system is required to define departments, secrecy levels, and integrity levels, enabling the principle of least privilege.
  3. Dynamic Policy Management: Mechanisms for declassification and endorsement are crucial to relax data control constraints when authorized.

P4Control's solution is built upon an extension of the Flume DFC model, a well-known operating system-level DFC model, adapted for network-level enforcement. This extension inherits Flume's security guarantees while introducing network-specific capabilities. The model assigns tags to both subjects (e.g., processes, users) and objects (e.g., files, network connections). These tags form DFC labels that encode various categories, such as departmental affiliation, confidentiality levels (e.g., "top secret"), and integrity attributes. The system rigorously adheres to safe message rules, ensuring that DFC labels propagate correctly with all system activities and network communications, preserving both secrecy and integrity. It supports decentralized privilege, allowing data owners to delegate permissions for declassification or endorsement. Crucially, the model incorporates the labeling of network packets themselves, embedding DFC context directly into network traffic to extend DFC's visibility to the network layer.

Enforcing such a comprehensive DFC model at network line rate demands specific technical requirements:

  • Network Level: The data plane must be capable of processing customized packet headers carrying DFC context without rerouting traffic to commodity servers or introducing significant processing overhead. Furthermore, it must enforce custom DFC controls on network connections on the fly, maintaining network line rate.
  • Host Level: Host modifications must be minimal and transparent, avoiding extensive kernel source code changes to ensure compatibility and lightweight operation. A robust mechanism is needed to propagate DFC labels within entities inside a host and between different hosts across the network, preserving DFC context end-to-end.

These stringent requirements are met by two key enablers:

  1. Programmable Switches: These switches offer a programmable data plane, allowing administrators to define custom packet processing logic directly within the switch hardware. P4Control leverages this to define custom DFC packet headers and process them at line rate, achieving speeds comparable to typical switch operations.
  2. eBPF Technology: This allows extending kernel capabilities without modifying the kernel's source code. P4Control uses eBPF to deploy a host agent that tracks internal system activities (e.g., process invocation, file access) and hooks into the network stack to incorporate DFC context into outgoing packets and extract it from incoming ones, maintaining persistence between host and network levels.

P4Control Architecture

The P4Control architecture comprises a switch component for in-network DFC enforcement and an eBPF agent for host-level DFC context propagation.

Switch Component

To extend DFC context to programmable switches, P4Control designs a custom DFC packet header. This header is indicated by a specific marker in the fragmentation field of the IP header, allowing programmable switches to identify and parse the DFC context. The switch data plane utilizes its custom packet processing capabilities to perform in-network DFC policy enforcement. DFC policies are maintained within the data plane, where network connections carrying DFC labels are matched against these policies, and security decisions (e.g., drop, allow, modify) are enforced instantly. The data plane also supports in-network declassifications and endorsements, allowing DFC labels to be modified (tags added or removed) on the fly as per policy.

eBPF Agent

The eBPF agent operates transparently within the operating system, attached to three critical hooks:

  1. XDP_ERIS Hook: Attached to the ingress path, this hook is responsible for propagating DFC labels from incoming network packets to the receiving process inside the host.
  2. Intra-Host Activity Hook: This hook monitors and propagates DFC labels during intra-host activities, such as process invocation, file creation, or inter-process communication. It ensures that the DFC context merges and tracks information flows within the host.
  3. TC_AGRESS Hook: Attached to the egress path, this hook propagates DFC labels from the sending process to outgoing network packets, extending the DFC context back to the network level.

Resource Optimization and Policy Management

Programmable switches have limited resources, making it inefficient to append full DFC labels to every packet in a flow. P4Control employs a first packet optimization strategy: DFC labels are appended only to the first packet of a network flow. Once the programmable switch determines a security decision for this first packet, that decision can be applied to subsequent packets in the same flow without re-verification.

However, adding a decision entry to the switch's match-action table typically requires interaction with the control plane, which can introduce a delay. To address this gap time, P4Control utilizes a stateful hardware register within the data plane to buffer the decision. This register temporarily maintains the decision until the control plane successfully adds the corresponding entry to the match-action table, ensuring consistent enforcement for the entire flow. This technique is designed to support various network protocols, including TCP, UDP, and ICMP.

To simplify the definition and management of complex DFC policies, P4Control introduces Network Control Language (NetCL). NetCL abstracts the low-level programming complexities of programmable data planes, providing an expressive and user-friendly interface for network administrators. It includes:

  • Labeling functions: To initialize and assign DFC labels to processes, files, and network flows.
  • Security actions: To control network flows (e.g., allow, block).
  • Privilege actions: To enable declassification and endorsement of information flows.

NetCL employs an efficient compiler that translates these high-level policies into the programmable switch's configuration. Furthermore, it supports dynamic updates to deployed DFC policies without requiring a switch restart, allowing for agile adaptation to changing enterprise requirements.

Demo / Proof of Concept

▶ Watch: Demonstration: How DFC labels propagate across hosts and network (5:05)

The talk illustrated P4Control's capabilities using a typical enterprise network scenario involving Alice, an admin host, and a protected server, alongside other departments. The network administrator's initial policy allows only the dev admin host to access the server, blocking all other direct connections. Alice is granted dual access to both the sales and developers departments, a common enterprise requirement.

The demonstration scenario unfolds as follows:

  1. Initial Compromise: An external attacker exploits a zero-day vulnerability in Bob's machine, compromising it. Bob's machine is in the sales department.
  2. Lateral Movement: The attacker scans the network and identifies Alice, who has access to both sales and developers departments. The attacker then compromises Alice's machine, effectively moving laterally from Bob (sales) to Alice (sales/developers).
  3. Pivoting and Server Access Attempt: From Alice's compromised machine, the attacker pivots into the developers department, which is allowed by the firewall policy (Alice's machine has legitimate access). The attacker then attempts to establish a connection to the server from Alice's machine, now acting as a compromised "dev admin" host.

P4Control intervenes with specific NetCL policies:

  • Initial DFC Labeling: NetCL policies are defined to initialize DFC labels for processes and files within hosts. For instance, processes on Bob's machine might carry a "sales" tag, while processes on Alice's machine initially carry "sales" and "developers" tags.
  • Policy Against Lateral Movement: When the attacker compromises Bob and then Alice, the P4Control host agent on Alice's machine merges the DFC labels. The malicious process on Alice's machine will now carry both the original "developers" tag (from Alice's legitimate access) and the "sales" tag (propagated from the compromised Bob).
  • Preventing Unauthorized Access: A crucial NetCL policy is added to prevent any connection carrying the "sales" tag from reaching the server. When the attacker attempts to connect to the server from the compromised Alice machine, the programmable switch inspects the DFC label in the packet. Detecting the "sales" tag, the switch immediately drops the connection in real-time, preventing the final stage of the cross-host attack.

The talk also demonstrated declassification. Consider a server holding "top secret" data, with a NetCL policy initially preventing any "top secret" data from leaving it. To allow authorized access, a specific declassification rule is added: remove the "top secret" tag only when the destination is the "dev admin" host. This policy allows data, initially labeled "top secret," to be sent to the dev admin, but with the "top secret" tag removed, effectively declassifying it for that specific, authorized flow. This showcases P4Control's ability to enforce dynamic and context-aware information flow policies.

The prototype implementation consists of 3200 lines of code, encompassing the NetCL compiler, eBPF programs, the switch program, and the switch control plane function. Evaluations in a physical testbed with a P4 switch and simulated enterprise topologies, alongside real-world datasets, confirmed P4Control's effectiveness against various internal and external IP attacks leveraging multiple protocols and applications. The system successfully blocked all attack traffic in real-time while maintaining high sending rates, demonstrating its ability to operate without affecting network performance.

Defensive Implications

▶ Watch: P4Control's threat model and challenges for end-to-end visibility (6:00)

P4Control offers profound defensive implications, transforming existing network infrastructure into a robust backbone for real-time defense against sophisticated cross-host attacks. Its core strength lies in bridging the visibility gap between host and network layers, providing defenders with an unprecedented ability to monitor and control information flows.

The immediate implication for defenders is the ability to prevent lateral movement and unauthorized data exfiltration in real-time. By propagating DFC labels from processes to network packets and enforcing policies at line rate within the programmable data plane, P4Control allows for instantaneous blocking of malicious connections that carry unauthorized or tainted information. This moves security beyond reactive forensic analysis to proactive, preventative measures, significantly reducing the window of opportunity for attackers to cause damage.

P4Control facilitates the realization of a Zero Trust Architecture (ZTA), a security model widely advocated by organizations and governmental entities (e.g., the recent White House Memo). ZTA removes implicit trust within networks, requiring explicit verification for every access request. P4Control's in-network DFC enforcement provides a foundational mechanism for ZTA by:

  • Precise Control: DFC labels allow for highly granular access control based on the actual context and sensitivity of the information being transmitted, rather than just IP addresses or ports.
  • Continuous Verification: Every packet carries its DFC context, enabling continuous verification of information flows against established policies at every network hop.
  • Dynamic Adaptation: NetCL allows security policies to be dynamically updated and adapted to changing enterprise requirements without network downtime, enabling an agile Zero Trust posture.

Defenders should consider the following actions to leverage P4Control's capabilities:

  1. Invest in Programmable Networking Infrastructure: Organizations should explore deploying programmable switches that support P4, recognizing them as critical components for future-proof security architectures.
  2. Deploy eBPF-based Host Agents: Integrate lightweight eBPF agents on host machines to transparently extract and inject DFC context from processes into network traffic, ensuring end-to-end visibility.
  3. Develop Granular DFC Policies with NetCL: Network administrators should define comprehensive DFC policies using NetCL to label data, processes, and network segments according to their sensitivity and integrity requirements. This includes defining rules for declassification and endorsement to manage legitimate information sharing.
  4. Monitor DFC Labels for Anomalous Flows: Implement monitoring and alerting systems that can detect deviations from established DFC policies, indicating potential compromise or unauthorized information flow.

P4Control's ability to support up to 256 different DFC tags and 12,000 active NetCL policies within the data plane, combined with negligible latency overhead (only 110 nanoseconds at the network side and 1 to 7 microseconds for the host agent), makes it a practical and scalable solution for large enterprise environments. By transforming the network into an active security enforcer, P4Control empowers defenders to build more resilient, context-aware, and real-time defensive postures against the most sophisticated cyber threats.

Key Takeaways

  • P4Control introduces the first network defense capable of enforcing Decentralized Information Flow Control (DFC) at line rate within the network, effectively preventing cross-host attacks in real-time.
  • The system leverages programmable switches (P4) for in-network policy enforcement and eBPF for transparent, lightweight host-level DFC context propagation, bridging the visibility gap between hosts and the network.
  • NetCL (Network Control Language) simplifies the definition of complex secrecy, integrity, declassification, and endorsement policies, enabling dynamic updates without requiring switch restarts.
  • P4Control demonstrates high performance and scalability, supporting up to 256 DFC tags and 12,000 active policies with minimal latency overhead (110 ns in-network, 1-7 µs host agent).
  • By providing granular, real-time control over information flows, P4Control serves as a critical enabler for realizing robust Zero Trust Architectures, moving away from implicit trust to explicit verification for all network interactions.

About the Speaker(s)

Osama Bajaber is a PhD student at Virginia Tech. His research focuses on network security, particularly leveraging programmable data planes and advanced kernel technologies like eBPF to build novel defense mechanisms against sophisticated cyberattacks. This work, P4Control, represents a significant contribution to real-time information flow control in modern networks.

Dr. Bo Ji and Dr. Peng Gao are advisors on the P4Control project, affiliated with Virginia Tech. Their expertise likely encompasses areas such as network systems, distributed systems, and security, guiding the research and development of innovative solutions like P4Control.

Reviews

Dr. Zero (Offensive Security Researcher) — MUST SEE

P4Control delivers a genuinely novel and technically deep solution for real-time cross-host attack prevention. By extending Decentralized Information Flow Control into the network fabric via programmable switches and eBPF, it offers unprecedented line-rate enforcement against lateral movement, directly addressing a critical gap in Zero Trust architectures. This is the kind of foundational work that actually shifts the defensive paradigm.

Heather Calloway (CISO) — STRONG ACCEPT

This talk presents a compelling and technically robust approach to real-time, in-network defense against lateral movement and unauthorized data exfiltration. By extending Decentralized Information Flow Control into the programmable network fabric, it offers a foundational technology for achieving true Zero Trust architectures.

→ Top-rated talks at IEEE Symposium on Security and Privacy 2024

All talks from IEEE Symposium on Security and Privacy 2024