Chhoyhopper: A Moving Target Defense with IPv6
A. S. M. Rizvi, John Heidemann · 2022
Our insight is that only a discovery-resistant moving target can elude scanners.We describe Chhoyhopper 1 , using the vast IPv6 address space to conceal publicly available services.The server hops to different IPv6 addresses in a pattern based on a shared, pre-distributed secret and the time-of-day.A client with the shared secret can match this pattern to find the server.As with SSH [33], we target services for small groups where out-of-band sharing of secrets (our hop key, or ssh's per-user keys) is viable; our approach can scale to support millions of such small groups.By hopping over a /64 prefix, any service cannot be found by active scanners, and passively observed information is useless after two minutes.We expect our system to be used by small organizations who want to protect their specific services used by their group from active scanners and brute-force attacks.Since the server hops over addresses, our system provides protection against DDoS attacks targeted to a fixed address.We make three new contributions: first, we show that IPv6 address hopping can be used to protect existing services ( §IV).Prior work suggested daily address changes for IoT devices with new services [19].We instead propose changing addresses every minute, and show how to apply this approach to existing popular services like SSH and HTTPS.We provide a common hopping design that can be used by multiple services.To the best of our knowledge, this is the first design of a moving target defense for SSH and HTTPS utilizing IPv6.Second, we show how to support web security with TLS by adding support for DNS-based TLS certificates to our core hopping protocol ( §IV-F).Finally, we propose a new approach to accommodate long-lived connections in the face of frequent address changes ( §IV-D).We use ip6tables rules to retain the existing connections to a fixed internal address but changing NAT rules allow new connections only with the current IPv6 addresses.Our deployment is user friendly, and works similarly like the current client applications ( §V).Availability: Our implementation is freely