Kernel-Bypass Based Fast Detection Method for IPv6 Extension Header Threats
Bin Lin, Haojie Zhu, Liancheng Zhang, Jichang Wang, Wenhao Xia · 2024
Existing threat detection techniques for IPv6 extension headers suffer from issues such as high packet loss rates, low processing speeds as network traffic scales up, and incomplete detection of threat types. To address these shortcomings, a Kernel-Bypass based Fast Detection Method for IPv6 Extension Header Threats (KB-FD6) is proposed. Firstly, leveraging DPDK to swiftly capture and process IPv6 packets directly from the network interface card bypasses the Linux kernel protocol stack, thereby enhancing packet processing speeds. Subsequently, features are constructed for common IPv6 extension header threats, enabling effective identification of various types of common IPv6 extension header threats through feature matching of collected IPv6 packets. Upon threat detection, alerts are triggered, and logs are recorded. Comparative testing against Suricata in an IPv6 network environment demonstrates that KB-FD6 not only detects all 8 classes of common IPv6 extension header threats but also achieves a 73.4% increase in packet capture rate and a 72.87% improvement in average packet processing speed under high-scale network traffic conditions.