Elective Advanced Networking with IPv6

Advanced Networking with IPv6Unit 412 min read

IPv6 Security & QoS: Mechanisms, Attacks & Traffic Control

Unit 4 of Advanced Networking with IPv6 explores IPv6’s built-in security features (IPSec, AAA, cryptographic extensions) and Quality of Service (QoS) mechanisms (traffic classes, flow labels, DiffServ), comparing them to IPv4 while analyzing real-world attacks and optimizations in Nepalese and global networks like eSe

TAKEAWAYS:

  • IPv6 integrates IPSec as mandatory, using AH (Authentication Header) and ESP (Encapsulating Security Payload) for confidentiality/integrity, unlike IPv4’s optional IPSec.
  • Quality of Service (QoS) in IPv6 relies on Traffic Class (8-bit DSCP) and Flow Label (20-bit) for per-flow prioritization, replacing IPv4’s ToS field.
  • Common IPv6 attacks include Neighbor Discovery (ND) spoofing, Router Advertisement (RA) attacks, and IPv6-over-IPv4 tunneling exploits—mitigated via Secure Neighbor Discovery (SEND) and Cryptographically Generated Addresses (CGA).
  • DiffServ (Differentiated Services) in IPv6 uses Traffic Class to mark packets for prioritization (e.g., VoIP over file transfers), while IntServ (RSVPv6) reserves resources for real-time flows.
  • Transition security risks: IPv4/IPv6 dual-stack deployments can leak metadata (e.g., 6to4 tunnels exposing internal IPv6 addresses).
  • Nepalese applications: Ncell’s VoLTE uses IPv6 Flow Labels for low-latency calls, while eSewa’s payment gateway relies on IPSec ESP for transaction integrity.

1. Security in IPv6: Built-in vs. IPv4

IPv6 was designed with security as a core feature, unlike IPv4 where security was an afterthought. The two primary mechanisms are IPSec and Authentication mechanisms for Neighbor Discovery (ND).

sequenceDiagram
    participant A as Victim Device
    participant B as Attacker
    participant C as Legit Router
    A->>C: Sends Router Solicitation (RS)
    B->>A: Spoofed Router Advertisement (RA) with malicious gateway
    A->>B: Updates default route to attacker
    B->>A: Intercepts all traffic
    Note right of A: **RA Spoofing Attack**
    Note right of B: **Mitigation: SEND + RAG**
Neighbor Discovery (ND) RA Spoofing Attack Flow (Ncell VoLTE towers vulnerable without SEND)
08162431Version4 bitsTraffic Class8 bitsFlow Label20 bitsPayload Length16 bitsNext Header8 bitsHop Limit8 bitsSource Address (128-bit)128 bitsDestination Address (128-bit)128 bits
IPv6 Header with IPSec AH/ESP integration (AH/ESP replace 'Next Header' for security fields)

1.1 IPSec in IPv6: Mandatory vs. Optional

stateDiagram-v2
    [*] --> IPv6_Packet
    IPv6_Packet --> AH: {Authentication Header}
    IPv6_Packet --> ESP: {Encapsulating Security Payload}
    AH --> Integrity: "HMAC-SHA-256"
    ESP --> Confidentiality: "AES-256"
    ESP --> Integrity: "HMAC-SHA-256"
    AH --> No_Confidentiality
    ESP --> Optional_Integrity
    AH --> IPv6_Header
    ESP --> IPv6_Header
    IPv6_Header --> [*]
  • Authentication Header (AH):

    • Provides data integrity and authentication (via HMAC).
    • Does not encrypt payload (confidentiality).
    • Used in Ncell’s core network to verify signaling messages between towers.
  • Encapsulating Security Payload (ESP):

    • Provides confidentiality (encryption), integrity, and optional authentication.
    • Uses AES-256 or 3DES for encryption.
    • Example: eSewa’s payment API uses ESP to secure transaction data between user devices and banks.

Comparison with IPv4 IPSec:

Feature IPv6 IPSec IPv4 IPSec
Mandatory? Yes (in most implementations) No (optional)
Header Format Integrated into IPv6 header Requires separate header (AH/ESP)
Default Algorithm AES-256, SHA-256 Depends on implementation (often MD5)
Transition Risk Vulnerable in dual-stack setups More mature but less secure

1.2 Neighbor Discovery (ND) Security

IPv6’s Neighbor Discovery Protocol (NDP) replaces IPv4’s ARP and ICMP Router Discovery. However, it is vulnerable to attacks like:

  • Router Advertisement (RA) Spoofing: Fake RAs redirect traffic to malicious routers.
  • Neighbor Solicitation (NS) Flooding: Overwhelms a target with NS messages.
  • Man-in-the-Middle (MITM): Exploits lack of authentication in NDP.

Mitigations:

  • Secure Neighbor Discovery (SEND):
    • Uses Cryptographically Generated Addresses (CGA) to bind IPv6 addresses to public keys.
    • Digital signatures verify ND messages.
  • Router Advertisement Guard (RAG):
    • Filters unauthorized RAs (used in NTC’s IPv6 backbone).

Worked Example: RA Spoofing Attack in Kathmandu Traffic Monitoring Assume a hacker in Thapathali spoofs a RA to redirect traffic from Nepal Police’s traffic cameras to their own server.

  1. Victim device receives a fake RA with a malicious link-local address.
  2. Device updates its default gateway to the attacker’s router.
  3. All traffic from the camera is intercepted. Prevention: Deploy SEND + RAG at the traffic control center’s gateway.

2. Quality of Service (QoS) in IPv6

QoS ensures critical traffic (e.g., VoIP, video) gets priority over best-effort data. IPv6 improves QoS with Traffic Class and Flow Label.

EF (DSCP 46)AF21 (DSCP 10)Best Effort (DSCP 0)Ncell TowerNTC Core RouterUser DeviceYouTube Server
Nepalese YouTube QoS: Video (EF) prioritized over ads (AF21) and comments (Best Effort)

2.1 Traffic Class (Differentiated Services Code Point - DSCP)

  • Replaces IPv4’s Type of Service (ToS) field (8 bits).
  • Uses DSCP (6 bits) for per-hop behaviors (PHBs) like:
    • Expedited Forwarding (EF): Low loss, low latency (VoIP).
    • Assured Forwarding (AF): Differentiated service classes (e.g., AF11 for email, AF41 for file transfers).

Example: YouTube Streaming in Nepal

  • Traffic Class = EF (DSCP 46) for video packets.
  • AF21 (DSCP 10) for ads (lower priority).
  • Best Effort (DSCP 0) for comments.

2.2 Flow Label for Per-Flow QoS

  • 20-bit Flow Label identifies a sequence of packets for end-to-end QoS.
  • Used by RSVPv6 (Resource Reservation Protocol) to reserve bandwidth.
  • Example: Pathao’s ride-hailing app uses Flow Labels to prioritize GPS updates over chat messages.

Flow Label Fields:

0                   1                   2                   3
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
| Traffic Class |   Flow Label (20 bits)                    |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+

Comparison: IPv4 vs. IPv6 QoS

Mechanism IPv4 IPv6
Field ToS (8 bits) Traffic Class (8 bits) + Flow Label (20 bits)
Per-Hop Behavior DSCP (6 bits) DSCP (6 bits) + Flow Label
End-to-End QoS Requires RSVP (not widely used) Built-in Flow Label + RSVPv6
Example Use Skype (DSCP EF) Ncell VoLTE (Flow Label + EF)

2.3 IntServ (RSVPv6) for Resource Reservation

  • RSVPv6 (Resource Reservation Protocol) reserves bandwidth for real-time flows.
  • Used in Nepal’s NTC fiber backbone for IPTV and emergency services.
  • Example: Nepal Police’s video conferencing reserves 1 Mbps with RSVPv6.

RSVPv6 Message Exchange (Simplified):

sequenceDiagram
    participant Sender as Police HQ (Sender)
    participant Router1 as NTC Router 1
    participant Router2 as NTC Router 2
    participant Receiver as District Office (Receiver)

    Sender->>Router1: PATH (Reserve 1 Mbps)
    Router1->>Router2: PATH
    Router2->>Receiver: PATH
    Receiver-->>Router2: RESV (Confirm)
    Router2-->>Router1: RESV
    Router1-->>Sender: RESV Confirmed

3. Common IPv6 Security Attacks & Mitigations

Attack Description Mitigation
RA Spoofing Fake RAs redirect traffic to attacker’s router. SEND + RAG
NS Flooding Overwhelms target with NS messages to deplete resources. Rate limiting on routers
6to4 Tunneling Exploits IPv6-over-IPv4 tunnels leak internal IPv6 addresses. Disable 6to4, use native IPv6
DDoS via IPv6 Amplification attacks (e.g., DNS64 misconfigurations). Filter spoofed source addresses
IPv6 Scan Attacks Scanning for IPv6-enabled hosts (e.g., fe80::/10 link-local). Disable unused IPv6 services

Real-World Example: Daraz’s IPv6 Migration

  • Daraz initially used 6to4 tunneling for IPv6, but attackers exploited it to leak internal server IPs.
  • Solution: Switched to native IPv6 with SEND-enabled ND and firewall rules blocking unsolicited NS.

4. IPv6 QoS in Nepalese Networks

4.1 Ncell’s VoLTE QoS

  • Uses Flow Labels to prioritize VoLTE calls over data.
  • Traffic Class = EF (DSCP 46) for RTP packets.
  • RSVPv6 reserves 128 kbps for each call.

4.2 NTC’s IPTV QoS

  • Traffic Class = AF41 (DSCP 34) for video streams.
  • AF21 (DSCP 10) for interactive menus.
  • Best Effort (DSCP 0) for background updates.

4.3 eSewa’s Payment Gateway

  • ESP (AES-256) encrypts transaction data.
  • Traffic Class = AF31 (DSCP 26) for high-priority payments.
  • Flow Labels ensure low latency for real-time fraud detection.

5. IPv4/IPv6 Transition Security Risks

When networks run both IPv4 and IPv6, attackers exploit dual-stack vulnerabilities:

  • IPv6 Leakage: Applications may leak IPv6 addresses (e.g., via WebRTC).
  • Tunnel Misconfigurations: Teredo, 6to4, or ISATAP tunnels can be hijacked.
  • Metadata Exposure: IPv6 traffic can reveal internal topology.

Mitigation Strategies:

  1. Disable IPv6 on unneeded interfaces (if not required).
  2. Use Firewall Rules to block unsolicited IPv6 traffic.
  3. Deploy SEND for ND security.
  4. Monitor with SIEM (e.g., Splunk) for suspicious IPv6 activity.

## In the real world

  1. Ncell’s VoLTE Calls

    • Idea Used: IPv6 Flow Labels + Traffic Class (EF)
    • How: Each VoLTE call gets a unique Flow Label and DSCP 46 (EF) to ensure low latency and jitter-free audio. Without this, calls would drop during peak hours (e.g., 7–9 PM in Kathmandu).
  2. eSewa’s Payment Security

    • Idea Used: IPSec ESP (AES-256) + Traffic Class (AF31)
    • How: When you transfer money via eSewa, the transaction packet is encrypted with ESP and marked with AF31 to bypass slower queues. If an attacker intercepts the packet, they cannot decrypt it without the pre-shared key.
  3. YouTube’s Adaptive Streaming in Nepal

    • Idea Used: Differentiated Services (Traffic Class)
    • How: YouTube prioritizes video chunks (DSCP 46) over ads (DSCP 10). During Nepal’s monsoon season (when NTC links slow down), this ensures the video buffer doesn’t stall while ads load later.

## Exam Tip

  1. Security Questions (30% weight):

    • Must-know: IPSec AH vs. ESP, SEND, RA Guard.
    • Common Pitfall: Confusing IPv4 IPSec (optional) with IPv6 IPSec (mandatory).
    • Exam Trick: For ND attacks, always mention SEND + CGA as the solution.
  2. QoS Questions (40% weight):

    • Traffic Class vs. Flow Label:
      • Traffic Class = Per-hop behavior (like DSCP in IPv4).
      • Flow Label = End-to-end QoS (unique per flow).
    • Worked Example: If asked about Ncell VoLTE, describe Flow Label + EF (DSCP 46).
  3. Transition Mechanisms (20% weight):

    • 6to4 vs. Teredo: Know their security risks (e.g., 6to4 leaks IPs).
    • Dual-Stack Risks: Always mention metadata exposure and firewall rules as mitigations.
  4. Real-World Scenarios (10% weight):

    • eSewa: IPSec ESP + Traffic Class.
    • Ncell VoLTE: Flow Label + RSVPv6.
    • NTC IPTV: AF41 for video, AF21 for menus.

Pro Tip: Draw IPv6 header diagrams (with AH/ESP/Traffic Class/Flow Label) in exams—they fetch extra marks for clarity.


Based on the TU BSc CSIT syllabus for Advanced Networking with IPv6, unit 4.

Discussion

Loading…