Don't Forget to Lock the Back Door! A Characterization of IPv6 Network Security Policy
Jakub Czyz, Matthew J. Luckie, Mark Allman, Michael D. Bailey
摘要
There is growing operational awareness of the challenges in securely operating IPv6 networks. Through a measurement study of 520,000 dual-stack servers and 25,000 dual-stack routers, we examine the extent to which security policy codified in IPv4 has also been deployed in IPv6. We find several high-value target applications with a comparatively open security policy in IPv6 including: (i) SSH, Telnet, SNMP, are more than twice as open on routers in IPv6 as they are in IPv4; (ii) nearly half of routers with BGP open were only open in IPv6; and (iii) in the server dataset, SNMP was twice as open in IPv6 as in IPv4. We conduct a detailed study of where port blocking policy is being applied and find that protocol openness discrepancies are consistent within network boundaries, suggesting a systemic failure in organizations to deploy consistent security policy. We successfully communicate our findings with twelve network operators and all twelve confirm that the relative openness was unintentional. Ten of the twelve immediately moved to deploy a congruent IPv6 security policy, reflecting real operational concern. Finally, we revisit the belief that the security impact of this comparative openness in IPv6 is mitigated by the infeasibility of IPv6 network-wide scanning-we find that, for both of our datasets, host addressing practices make discovering these high-value hosts feasible by scanning alone. To help operators accurately measure their own IPv6 security posture, we make our probing system publicly available. Permission to freely reproduce all or part of this paper for noncommercial purposes is granted provided that copies bear this notice and the full citation on the first page. Reproduction for commercial purposes is strictly prohibited without the prior written consent of the Internet Society, the first-named author (for reproduction of an entire paper only), and the author's employer if the paper was prepared within the scope of employment.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper12
- You've Got Vulnerability: Exploring Effective Vulnerability NotificationsFrank Li, Zakir Durumeric, Jakub Czyz, Mohammad Karami 等USENIX Security 2016 · 被引用 149 次
- Investigating System Operators' Perspective on Security MisconfigurationsConstanze Dietrich, Katharina Krombholz, Kevin Borgolte, Tobias FiebigCCS 2018 · 被引用 116 次
- Network Hygiene, Incentives, and Regulation: Deployment of Source Address Validation in the InternetMatthew J. Luckie, Robert Beverly, Ryan Koga, Ken Keys 等CCS 2019 · 被引用 89 次
- Didn't You Hear Me? - Towards More Successful Web Vulnerability NotificationsBen Stock, Giancarlo Pellegrino, Frank Li, Michael Backes 等NDSS 2018 · 被引用 86 次
- 6GAN: IPv6 Multi-Pattern Target Generation via Generative Adversarial Nets with Reinforcement LearningTianyu Cui, Gaopeng Gou, Gang Xiong, Chang Liu 等INFOCOM 2021 · 被引用 59 次
相关 Paper
- Your Router is My Prober: Measuring IPv6 Networks via ICMP Rate Limiting Side ChannelsLong Pan, Jiahai Yang, Lin He, Zhiliang Wang 等NDSS 2023
- Enumerating Active IPv6 Hosts for Large-Scale Security Scans via DNSSEC-Signed Reverse ZonesKevin Borgolte, Shuang Hao, Tobias Fiebig, Giovanni VignaS&P 2018 · 被引用 48 次
- On Using Application-Layer Middlebox Protocols for Peeking Behind NAT GatewaysTeemu Rytilahti, Thorsten HolzNDSS 2020
- Exploring the Exposure of IPv6 End-Host NetworksHugo Hue, Abhishek Bhaskar, Amanda Hsu, Paul Pearce 等CCS 2026
- AddrMiner: A Comprehensive Global Active IPv6 Address Discovery SystemGuanglei Song, Jiahai Yang, Lin He, Zhiliang Wang 等USENIX ATC 2022 · 被引用 55 次
