The IP Identification (IP-ID) field, which provides fragmentation and reassembly support for the network layer, is included in an extension header in IPv6, unlike in IPv4, where it is a fixed field. By sending packets such as ICMPv6 Too Big, it is possible to induce fragmented responses and thereby retrieve IP-IDs from remote IPv6 hosts. In this study, we propose a framework for active probing to obtain the IP-ID sequences of IPv6 targets. By probing over 20 million IPv6 addresses, we found that IPv6 hosts can be induced to fragment primarily depending on their device type and security policy. Furthermore, we built a classifier with an accuracy of 98.4% to distinguish different IP-ID behaviors. We discovered that 46.1% of addresses still use predictable IP-IDs, which can be susceptible to various network attacks, such as IP spoofing and session hijacking.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A Closer Look at IPv6 IP-ID Behavior in the Wild

  • Fengyuan Huang,
  • Yifan Yang,
  • Zhenzhong Yang,
  • Bingnan Hou,
  • Yingwen Chen,
  • Zhiping Cai

摘要

The IP Identification (IP-ID) field, which provides fragmentation and reassembly support for the network layer, is included in an extension header in IPv6, unlike in IPv4, where it is a fixed field. By sending packets such as ICMPv6 Too Big, it is possible to induce fragmented responses and thereby retrieve IP-IDs from remote IPv6 hosts. In this study, we propose a framework for active probing to obtain the IP-ID sequences of IPv6 targets. By probing over 20 million IPv6 addresses, we found that IPv6 hosts can be induced to fragment primarily depending on their device type and security policy. Furthermore, we built a classifier with an accuracy of 98.4% to distinguish different IP-ID behaviors. We discovered that 46.1% of addresses still use predictable IP-IDs, which can be susceptible to various network attacks, such as IP spoofing and session hijacking.