Don't Forget to Lock the Back Door! A Characterization of IPv6 Network Security Policy
Jakub Czyz, Matthew J. Luckie, Mark Allman, Michael D. Bailey
Abstract
There is growing operational awareness of the challenges in securely operating IPv6 networks. Through a measurement study of 520,000 dual-stack servers and 25,000 dual-stack routers, we examine the extent to which security policy codified in IPv4 has also been deployed in IPv6. We find several high-value target applications with a comparatively open security policy in IPv6 including: (i) SSH, Telnet, SNMP, are more than twice as open on routers in IPv6 as they are in IPv4; (ii) nearly half of routers with BGP open were only open in IPv6; and (iii) in the server dataset, SNMP was twice as open in IPv6 as in IPv4. We conduct a detailed study of where port blocking policy is being applied and find that protocol openness discrepancies are consistent within network boundaries, suggesting a systemic failure in organizations to deploy consistent security policy. We successfully communicate our findings with twelve network operators and all twelve confirm that the relative openness was unintentional. Ten of the twelve immediately moved to deploy a congruent IPv6 security policy, reflecting real operational concern. Finally, we revisit the belief that the security impact of this comparative openness in IPv6 is mitigated by the infeasibility of IPv6 network-wide scanning-we find that, for both of our datasets, host addressing practices make discovering these high-value hosts feasible by scanning alone. To help operators accurately measure their own IPv6 security posture, we make our probing system publicly available. Permission to freely reproduce all or part of this paper for noncommercial purposes is granted provided that copies bear this notice and the full citation on the first page. Reproduction for commercial purposes is strictly prohibited without the prior written consent of the Internet Society, the first-named author (for reproduction of an entire paper only), and the author's employer if the paper was prepared within the scope of employment.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 1f6b1e37-c803-4324-a31c-3a5165d6234aCited by top-tier papers12
- You've Got Vulnerability: Exploring Effective Vulnerability NotificationsFrank Li, Zakir Durumeric, Jakub Czyz, Mohammad Karami et al.USENIX Security 2016 · 149 citations
- Investigating System Operators' Perspective on Security MisconfigurationsConstanze Dietrich, Katharina Krombholz, Kevin Borgolte, Tobias FiebigCCS 2018 · 116 citations
- Network Hygiene, Incentives, and Regulation: Deployment of Source Address Validation in the InternetMatthew J. Luckie, Robert Beverly, Ryan Koga, Ken Keys et al.CCS 2019 · 89 citations
- Didn't You Hear Me? - Towards More Successful Web Vulnerability NotificationsBen Stock, Giancarlo Pellegrino, Frank Li, Michael Backes et al.NDSS 2018 · 86 citations
- 6GAN: IPv6 Multi-Pattern Target Generation via Generative Adversarial Nets with Reinforcement LearningTianyu Cui, Gaopeng Gou, Gang Xiong, Chang Liu et al.INFOCOM 2021 · 59 citations
Related papers
- Your Router is My Prober: Measuring IPv6 Networks via ICMP Rate Limiting Side ChannelsLong Pan, Jiahai Yang, Lin He, Zhiliang Wang et al.NDSS 2023
- Enumerating Active IPv6 Hosts for Large-Scale Security Scans via DNSSEC-Signed Reverse ZonesKevin Borgolte, Shuang Hao, Tobias Fiebig, Giovanni VignaS&P 2018 · 48 citations
- On Using Application-Layer Middlebox Protocols for Peeking Behind NAT GatewaysTeemu Rytilahti, Thorsten HolzNDSS 2020
- Exploring the Exposure of IPv6 End-Host NetworksHugo Hue, Abhishek Bhaskar, Amanda Hsu, Paul Pearce et al.CCS 2026
- AddrMiner: A Comprehensive Global Active IPv6 Address Discovery SystemGuanglei Song, Jiahai Yang, Lin He, Zhiliang Wang et al.USENIX ATC 2022 · 55 citations
