Flaw Label: Exploiting IPv6 Flow Label
Jonathan Berger, Amit Klein, Benny Pinkas
Abstract
The IPv6 protocol was designed with security in mind. One of the changes that IPv6 has introduced over IPv4 is a new 20-bit flow label field in its protocol header. We show that remote servers can use the flow label field in order to assign a unique ID to each device when communicating with machines running Windows 10 (versions 1703 and higher), and Linux and Android (kernel versions 4.3 and higher). The servers are then able to associate the respective device IDs with subsequent transmissions sent from those machines. This identification is done by exploiting the flow label field generation logic and works across all browsers regardless of network changes. Furthermore, a variant of this attack also works passively, namely without actively triggering traffic from those machines. To design the attack we reverse-engineered and cryptanalyzed the Windows flow label generation code and inspected the Linux kernel flow label generation code. We provide a practical technique to partially extract the key used by each of these algorithms, and observe that this key can identify individual devices across networks, VPNs, browsers and privacy settings. We deployed a demo (for both Windows and Linux/Android) showing that key extraction and machine fingerprinting works in the wild, and tested it from networks around the world. 1 We use the term "fingerprinting" as a synonym for obtaining a device-ID. (i.e., it survives shutdown+startup). Both techniques generate a consistent device-ID regardless of network changes or the browser used, and are unaffected by IPv6 privacy mechanisms. These techniques are feasible and we have successfully tested our techniques in the wild.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 4c02f854-5074-464c-bc30-b8d469cb6056Cited by top-tier papers5
- Cross Layer Attacks and How to Use Them (for DNS Cache Poisoning, Device Tracking and More)Amit KleinS&P 2021 · 26 citations
- SiamHAN: IPv6 Address Correlation Attacks on TLS Encrypted Traffic via Siamese Heterogeneous Graph Attention NetworkTianyu Cui, Gaopeng Gou, Gang Xiong, Zhen Li et al.USENIX Security 2021 · 21 citations
- You Can Rand but You Can't Hide: A Holistic Security Analysis of Google Fuchsia's (and gVisor's) Network StackInon Kaplan, Ron Even, Amit KleinNDSS 2025
- Device Tracking via Linux's New TCP Source Port Selection AlgorithmMoshe Kol, Amit Klein, Yossi GiladUSENIX Security 2023
- IPvSeeYou: Exploiting Leaked Identifiers in IPv6 for Street-Level GeolocationErik C. Rye, Robert BeverlyS&P 2023
Builds on2
Related papers
- Clock Around the Clock: Time-Based Device FingerprintingIskander Sánchez-Rola, Igor Santos, Davide BalzarottiCCS 2018 · 91 citations
- DRAWN APART: A Device Identification Technique based on Remote GPU FingerprintingTomer Laor, Naif Mehanna, Antonin Durey, Vitaly Dyadyuk et al.NDSS 2022
- JavaScript Template Attacks: Automatically Inferring Host Information for Targeted ExploitsMichael Schwarz, Florian Lackner, Daniel GrussNDSS 2019 · 57 citations
- Beauty and the Beast: Diverting Modern Web Browsers to Build Unique Browser FingerprintsPierre Laperdrix, Walter Rudametkin, Benoit BaudryS&P 2016 · 279 citations
- Dedup Est Machina: Memory Deduplication as an Advanced Exploitation VectorErik Bosman, Kaveh Razavi, Herbert Bos, Cristiano GiuffridaS&P 2016 · 252 citations
