USENIX Security2026Top-tier venue
TED: Abusing Tunnel Hosts and IPv6 Extension Headers for Pulsing DoS Attacks
Le Gai, Zedong Jia, Lin He, Daguo Cheng, Chentian Wei, Ying Liu
Abstract
IP tunneling mechanisms are widely deployed to facilitate the Internet's transition from IPv4 to IPv6, yet their security implications remain insufficiently scrutinized. In this paper, we present TED, a novel pulsing denial-of-service attack that exploits structural vulnerabilities in IP tunneling and IPv6 Extension Headers (EHs) processing. Unlike prior reflection attacks that depend on application-layer services, TED operates entirely at the network layer, requiring no victim interaction, prolonged traffic accumulation, or protocol-specific dependencies. Delay lines are constructed by TED through nested EHs, capitalizing on the tunnel hosts' blind forwarding logic and lack of deep packet inspection. These artificial delay lines allow attackers to solve the send-time schedule problem, converging asynchronous, low-rate traffic into a destructive, high-magnitude pulse at the victim. Our Internet-wide measurement identified over 1.9 million vulnerable tunnel hosts acting as unwitting relays, including hosts within critical satellite infrastructure. Evaluation results demonstrate that TED achieves normalized pulse amplitude exceeding 180× while successfully evading existing low-rate and pulsing attack detection mechanisms based on specific application layer protocols. We discuss the root causes of these transitional vulnerabilities and possible mitigation strategies for network operators and equipment vendors.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on8
- A Multifaceted Look at Starlink PerformanceNitinder Mohan, Andrew E. Ferguson, Hendrik Cech, Rohan Bose et al.WWW 2024 · 154 citations
- Aggregate-based congestion control for pulse-wave DDoS defenseAlbert Gran Alcoz, Martin Strohmeier, Vincent Lenders, Laurent VanbeverSIGCOMM 2022 · 63 citations
- Scan, Test, Execute: Adversarial Tactics in Amplification DDoS AttacksHarm Griffioen, Kris Oosthoek, Paul van der Knaap, Christian DoerrCCS 2021 · 35 citations
- DNSBomb: A New Practical-and-Powerful Pulsing DoS Attack Exploiting DNS Queries-and-ResponsesXiang Li, Dashuai Wu, Haixin Duan, Qi LiS&P 2024 · 14 citations
- Haunted by Legacy: Discovering and Exploiting Vulnerable Tunnelling HostsAngelos Beitis, Mathy VanhoefUSENIX Security 2025
Related papers
- Temporal CDN-Convex Lens: A CDN-Assisted Practical Pulsing DDoS AttackRun Guo, Jianjun Chen, Yihang Wang, Keran Mu et al.USENIX Security 2023
- Lost in Encapsulation: Exploiting Open Tunnelling Hosts and Attacking Private NetworksAngelos Beitis, Mathy VanhoefUSENIX Security 2026
- CoordMail: Exploiting SMTP Timeout and Command Interaction to Coordinate Email Middleware for Convergence Amplification AttackRuixuan Li, Chaoyi Lu, Baojun Liu, Yanzhong Lin et al.NDSS 2026 · 1 citation
- AmpFuzz: Fuzzing for Amplification DDoS VulnerabilitiesJohannes Krupp, Ilya Grishchenko, Christian RossowUSENIX Security 2022
- Deterrence of Intelligent DDoS via Multi-Hop Traffic DivergenceYuanjie Li, Hewu Li, Zhizheng Lv, Xingkun Yao et al.CCS 2021 · 11 citations
