Routing Loop Attacks using IPv6 Tunnels
نویسندگان
چکیده
IPv6 is the future network layer protocol for the Internet. Since it is not compatible with its predecessor, some interoperability mechanisms were designed. An important category of these mechanisms is automatic tunnels, which enable IPv6 communication over an IPv4 network without prior configuration. This category includes ISATAP, 6to4 and Teredo. We present a novel class of attacks that exploit vulnerabilities in these tunnels. These attacks take advantage of inconsistencies between a tunnel’s overlay IPv6 routing state and the native IPv6 routing state. The attacks form routing loops which can be abused as a vehicle for traffic amplification to facilitate DoS attacks. We exhibit five attacks of this class. One of the presented attacks can DoS a Teredo server using a single packet. The exploited vulnerabilities are embedded in the design of the tunnels; hence any implementation of these tunnels may be vulnerable. In particular, the attacks were tested against the ISATAP, 6to4 and Teredo implementations of Windows Vista and Windows Server 2008 R2.
منابع مشابه
Routing Loop Attack Using IPv 6 Automatic Tunnels : Problem
This document is concerned with security vulnerabilities in IPv6-inIPv4 automatic tunnels. These vulnerabilities allow an attacker to take advantage of inconsistencies between the IPv4 routing state and the IPv6 routing state. The attack forms a routing loop that can be abused as a vehicle for traffic amplification to facilitate denialof-service (DoS) attacks. The first aim of this document is ...
متن کاملRFC 6324 Routing Loop Attack
This document is concerned with security vulnerabilities in IPv6-inIPv4 automatic tunnels. These vulnerabilities allow an attacker to take advantage of inconsistencies between the IPv4 routing state and the IPv6 routing state. The attack forms a routing loop that can be abused as a vehicle for traffic amplification to facilitate denialof-service (DoS) attacks. The first aim of this document is ...
متن کاملPacket Fragmentation in IPv6 over IPv4 Tunnels
Nowadays IPv6 over IPv4 tunnels are widely used to form the global IPv6 Internet. This paper analyzes a packet fragmentation problem in IPv6 over IPv4 tunnels due to the MTU difference between IPv6 and IPv4 layers, which would greatly degrade the performance of the tunnels if ever happened. It also demonstrates an ICMP based attack that could induce the problem and gives some advice on how to d...
متن کاملRecord Path Header for Triangle Routing Attacks in IPv6 Networks
Triangle routing is one of the serious attacks to the Internet infrastructure. It can be caused by malicious routers which misroute packets to wrong directions. This kind of attacks creates network problems such as network congestion, denial of service and network partition and results in degrade of network performance. This paper gives a comprehensive study on how the path analysis combats the...
متن کاملInternet Draft Routing Aspects Of IPv 6 Transition November 1994
This paper discusses routing aspects associated with the transition from IPv4 to IPv6. The approach outlined here is designed to be compatible with the Simple Internet Transition (SIT) mechanism. The proposals contained in this document are the opinions of the authors, and have not yet been discussed in detail by the working group. This document is intended as input to the IPNG, Tacit, and Ngtr...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2003