A Packet Fields Authenticity Check Based Detection Technology of IPv6 Spoofing Behaviors

Liancheng Zhang, Wenhao Xia, Xinyu Song, Lanxin Cheng, Wenwen Du, Xupan Ma · 2022

With the increasing popularity of IPv6 network deployment and application, more and more security problems of the IPv6 protocol mechanism and protocol stack are exposed. Among them, IPv6 network spoofing attacks are not only easy to implement, but also extremely harmful. However, current mainstream IPv6 intrusion detection tools (such as Suricata and 6shield) can only detect a small amount of IPv6 network spoofing behaviors. It is necessary and urgent to improve the effectiveness and accuracy of IPv6 network spoofing behaviors detection technologies. By the behavior characteristics analysis of typical IPv6 network spoofing attack tools in thc-IPv6 and IPv6toolkit, a packet fields authenticity check based detection technology of IPv6 spoofing behaviors is proposed. 6FakeDetector, an IPv6 network spoofing behaviors detection tool, is designed and implemented as well. The comparative test results between 6FakeDetector and 6shield show that in a typical IPv6 network testing environment, 6FakeDetector can detect 7 more types of IPv6 network spoofing attacks, such as fake DHCPv6 server attack.

Read the paper · More papers on PaperTik