Research on Security Protection Evasion Mechanism Based on IPv6 Fragment Headers
Bin Lin, Liancheng Zhang, Yi Guo, Hongtao Zhang, Yakai Fang · 2024
The IPv6 fragment headers are crucial for packet fragmentation but can be exploited to evade security systems, posing substantial threats. Despite RFC 7112 highlighting the implications of "IPv6 fragment evasion behavior", comprehensive evaluation is lacking, impeding assessment of compliance with standards. Concurrently, existing IPv6 fragment evasion behaviors have primarily focused on tiny/overlapping fragments, overlooking the combination of other IPv6 extension headers. Consequently, this paper proposes an IPv6 fragment evasion (FragEva6) behavior model, demonstrating the step-by-step construction process from the IPv6 header to the FragEva6 mechanism. Next, a test suite named FragEva6-Build encompassing 16 types of FragEva6 behaviors is realized through 3 steps. Subsequently, an evaluation of 17 mainstream operating systems and 4 security systems reveals that the latest versions of Windows and Apple operating systems comply with RFC 7112 when handling IPv6 fragmentations, while Linux operating systems exhibit partial non-compliance. Further, security systems (Windows Defender 20230503.1, ip6 tables 1.8.9, Suricata v6.0.12, and Snort v3.1.61.0) exhibit inadequate mitigation, leaving them susceptible to evasion threats through manipulation of IPv6 fragment headers. Finally, to illustrate the gravity of these behaviors, this study implements an on-link host scanning activity based on the FragEva6 mechanism, successfully evading firewalls and eliciting target responses.