A Closer Look at IPv6 IP-ID Behavior in the Wild
摘要
The IP Identification (IP-ID) field, which provides fragmentation and reassembly support for the network layer, is included in an extension header in IPv6, unlike in IPv4, where it is a fixed field. By sending packets such as ICMPv6 Too Big, it is possible to induce fragmented responses and thereby retrieve IP-IDs from remote IPv6 hosts. In this study, we propose a framework for active probing to obtain the IP-ID sequences of IPv6 targets. By probing over 20 million IPv6 addresses, we found that IPv6 hosts can be induced to fragment primarily depending on their device type and security policy. Furthermore, we built a classifier with an accuracy of 98.4% to distinguish different IP-ID behaviors. We discovered that 46.1% of addresses still use predictable IP-IDs, which can be susceptible to various network attacks, such as IP spoofing and session hijacking.