Follow the Scent: Defeating IPv6 Prefix Rotation Privacy

01/31/2021
by   Erik C. Rye, et al.
0

IPv6's large address space provides ample freedom for assigning addresses. To resist IP-based tracking, several techniques have been standardized to leverage this large address space, including privacy extensions and provider prefix rotation. Whereas in IPv4 many hosts may map to one address, e.g., with NAT, in IPv6 a single host may use many different public addresses. The use of many IPv6 addresses by a single host over time confounds not only adversarial tracking and traffic correlation attempts, but also traditional network measurements, logging, and defense mechanisms. We show that the intended anti-tracking capability of these widely deployed techniques is unwittingly subverted by edge routers that use legacy IPv6 addressing schemes with embedded unique identifiers. Via Internet-wide measurements, we find more than 9M affected customers across hundreds of networks worldwide. Using our technique, we demonstrate the ability of a passive adversary to correlate seemingly unrelated IPv6 traffic flows over time. Based on our findings, we contact equipment manufacturers and make recommendations to remediate this weaknesses in IPv6 infrastructure.

READ FULL TEXT
research
04/20/2022

SiamHAN: IPv6 Address Correlation Attacks on TLS Encrypted Traffic via Siamese Heterogeneous Graph Attention Network

Unlike IPv4 addresses, which are typically masked by a NAT, IPv6 address...
research
07/18/2018

FRVM: Flexible Random Virtual IP Multiplexing in Software-Defined Networks

Network address shuffling is one of moving target defense (MTD) techniqu...
research
07/13/2023

Target Acquired? Evaluating Target Generation Algorithms for IPv6

Internet measurements are a crucial foundation of IPv6-related research....
research
05/09/2019

Enhanced Performance and Privacy for TLS over TCP Fast Open

Small TCP flows make up the majority of web flows. For them, the TCP thr...
research
10/23/2017

Bootstrapping Active IPv6 Measurement with IPv4 and Public DNS

The IPv4 address space is small enough to allow exhaustive active measur...
research
10/07/2021

Attacks on Onion Discovery and Remedies via Self-Authenticating Traditional Addresses

Onion addresses encode their own public key. They are thus self-authenti...
research
02/24/2019

EUI-64 Considered Harmful

This position paper considers the privacy and security implications of E...

Please sign up or login with your details

Forgot password? Click here to reset