Advanced Networking with IPv6Unit 412 min read
IPv6 Security & QoS: Mechanisms, Attacks & Traffic Control
Unit 4 of Advanced Networking with IPv6 explores IPv6’s built-in security features (IPSec, AAA, cryptographic extensions) and Quality of Service (QoS) mechanisms (traffic classes, flow labels, DiffServ), comparing them to IPv4 while analyzing real-world attacks and optimizations in Nepalese and global networks like eSe
TAKEAWAYS:
- IPv6 integrates IPSec as mandatory, using AH (Authentication Header) and ESP (Encapsulating Security Payload) for confidentiality/integrity, unlike IPv4’s optional IPSec.
- Quality of Service (QoS) in IPv6 relies on Traffic Class (8-bit DSCP) and Flow Label (20-bit) for per-flow prioritization, replacing IPv4’s ToS field.
- Common IPv6 attacks include Neighbor Discovery (ND) spoofing, Router Advertisement (RA) attacks, and IPv6-over-IPv4 tunneling exploits—mitigated via Secure Neighbor Discovery (SEND) and Cryptographically Generated Addresses (CGA).
- DiffServ (Differentiated Services) in IPv6 uses Traffic Class to mark packets for prioritization (e.g., VoIP over file transfers), while IntServ (RSVPv6) reserves resources for real-time flows.
- Transition security risks: IPv4/IPv6 dual-stack deployments can leak metadata (e.g., 6to4 tunnels exposing internal IPv6 addresses).
- Nepalese applications: Ncell’s VoLTE uses IPv6 Flow Labels for low-latency calls, while eSewa’s payment gateway relies on IPSec ESP for transaction integrity.
1. Security in IPv6: Built-in vs. IPv4
IPv6 was designed with security as a core feature, unlike IPv4 where security was an afterthought. The two primary mechanisms are IPSec and Authentication mechanisms for Neighbor Discovery (ND).
sequenceDiagram
participant A as Victim Device
participant B as Attacker
participant C as Legit Router
A->>C: Sends Router Solicitation (RS)
B->>A: Spoofed Router Advertisement (RA) with malicious gateway
A->>B: Updates default route to attacker
B->>A: Intercepts all traffic
Note right of A: **RA Spoofing Attack**
Note right of B: **Mitigation: SEND + RAG**Neighbor Discovery (ND) RA Spoofing Attack Flow (Ncell VoLTE towers vulnerable without SEND)1.1 IPSec in IPv6: Mandatory vs. Optional
stateDiagram-v2
[*] --> IPv6_Packet
IPv6_Packet --> AH: {Authentication Header}
IPv6_Packet --> ESP: {Encapsulating Security Payload}
AH --> Integrity: "HMAC-SHA-256"
ESP --> Confidentiality: "AES-256"
ESP --> Integrity: "HMAC-SHA-256"
AH --> No_Confidentiality
ESP --> Optional_Integrity
AH --> IPv6_Header
ESP --> IPv6_Header
IPv6_Header --> [*]Authentication Header (AH):
- Provides data integrity and authentication (via HMAC).
- Does not encrypt payload (confidentiality).
- Used in Ncell’s core network to verify signaling messages between towers.
Encapsulating Security Payload (ESP):
- Provides confidentiality (encryption), integrity, and optional authentication.
- Uses AES-256 or 3DES for encryption.
- Example: eSewa’s payment API uses ESP to secure transaction data between user devices and banks.
Comparison with IPv4 IPSec:
| Feature | IPv6 IPSec | IPv4 IPSec |
|---|---|---|
| Mandatory? | Yes (in most implementations) | No (optional) |
| Header Format | Integrated into IPv6 header | Requires separate header (AH/ESP) |
| Default Algorithm | AES-256, SHA-256 | Depends on implementation (often MD5) |
| Transition Risk | Vulnerable in dual-stack setups | More mature but less secure |
1.2 Neighbor Discovery (ND) Security
IPv6’s Neighbor Discovery Protocol (NDP) replaces IPv4’s ARP and ICMP Router Discovery. However, it is vulnerable to attacks like:
- Router Advertisement (RA) Spoofing: Fake RAs redirect traffic to malicious routers.
- Neighbor Solicitation (NS) Flooding: Overwhelms a target with NS messages.
- Man-in-the-Middle (MITM): Exploits lack of authentication in NDP.
Mitigations:
- Secure Neighbor Discovery (SEND):
- Uses Cryptographically Generated Addresses (CGA) to bind IPv6 addresses to public keys.
- Digital signatures verify ND messages.
- Router Advertisement Guard (RAG):
- Filters unauthorized RAs (used in NTC’s IPv6 backbone).
Worked Example: RA Spoofing Attack in Kathmandu Traffic Monitoring Assume a hacker in Thapathali spoofs a RA to redirect traffic from Nepal Police’s traffic cameras to their own server.
- Victim device receives a fake RA with a malicious link-local address.
- Device updates its default gateway to the attacker’s router.
- All traffic from the camera is intercepted. Prevention: Deploy SEND + RAG at the traffic control center’s gateway.
2. Quality of Service (QoS) in IPv6
QoS ensures critical traffic (e.g., VoIP, video) gets priority over best-effort data. IPv6 improves QoS with Traffic Class and Flow Label.
2.1 Traffic Class (Differentiated Services Code Point - DSCP)
- Replaces IPv4’s Type of Service (ToS) field (8 bits).
- Uses DSCP (6 bits) for per-hop behaviors (PHBs) like:
- Expedited Forwarding (EF): Low loss, low latency (VoIP).
- Assured Forwarding (AF): Differentiated service classes (e.g., AF11 for email, AF41 for file transfers).
Example: YouTube Streaming in Nepal
- Traffic Class = EF (DSCP 46) for video packets.
- AF21 (DSCP 10) for ads (lower priority).
- Best Effort (DSCP 0) for comments.
2.2 Flow Label for Per-Flow QoS
- 20-bit Flow Label identifies a sequence of packets for end-to-end QoS.
- Used by RSVPv6 (Resource Reservation Protocol) to reserve bandwidth.
- Example: Pathao’s ride-hailing app uses Flow Labels to prioritize GPS updates over chat messages.
Flow Label Fields:
0 1 2 3
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
| Traffic Class | Flow Label (20 bits) |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
Comparison: IPv4 vs. IPv6 QoS
| Mechanism | IPv4 | IPv6 |
|---|---|---|
| Field | ToS (8 bits) | Traffic Class (8 bits) + Flow Label (20 bits) |
| Per-Hop Behavior | DSCP (6 bits) | DSCP (6 bits) + Flow Label |
| End-to-End QoS | Requires RSVP (not widely used) | Built-in Flow Label + RSVPv6 |
| Example Use | Skype (DSCP EF) | Ncell VoLTE (Flow Label + EF) |
2.3 IntServ (RSVPv6) for Resource Reservation
- RSVPv6 (Resource Reservation Protocol) reserves bandwidth for real-time flows.
- Used in Nepal’s NTC fiber backbone for IPTV and emergency services.
- Example: Nepal Police’s video conferencing reserves 1 Mbps with RSVPv6.
RSVPv6 Message Exchange (Simplified):
sequenceDiagram
participant Sender as Police HQ (Sender)
participant Router1 as NTC Router 1
participant Router2 as NTC Router 2
participant Receiver as District Office (Receiver)
Sender->>Router1: PATH (Reserve 1 Mbps)
Router1->>Router2: PATH
Router2->>Receiver: PATH
Receiver-->>Router2: RESV (Confirm)
Router2-->>Router1: RESV
Router1-->>Sender: RESV Confirmed3. Common IPv6 Security Attacks & Mitigations
| Attack | Description | Mitigation |
|---|---|---|
| RA Spoofing | Fake RAs redirect traffic to attacker’s router. | SEND + RAG |
| NS Flooding | Overwhelms target with NS messages to deplete resources. | Rate limiting on routers |
| 6to4 Tunneling Exploits | IPv6-over-IPv4 tunnels leak internal IPv6 addresses. | Disable 6to4, use native IPv6 |
| DDoS via IPv6 | Amplification attacks (e.g., DNS64 misconfigurations). | Filter spoofed source addresses |
| IPv6 Scan Attacks | Scanning for IPv6-enabled hosts (e.g., fe80::/10 link-local). |
Disable unused IPv6 services |
Real-World Example: Daraz’s IPv6 Migration
- Daraz initially used 6to4 tunneling for IPv6, but attackers exploited it to leak internal server IPs.
- Solution: Switched to native IPv6 with SEND-enabled ND and firewall rules blocking unsolicited NS.
4. IPv6 QoS in Nepalese Networks
4.1 Ncell’s VoLTE QoS
- Uses Flow Labels to prioritize VoLTE calls over data.
- Traffic Class = EF (DSCP 46) for RTP packets.
- RSVPv6 reserves 128 kbps for each call.
4.2 NTC’s IPTV QoS
- Traffic Class = AF41 (DSCP 34) for video streams.
- AF21 (DSCP 10) for interactive menus.
- Best Effort (DSCP 0) for background updates.
4.3 eSewa’s Payment Gateway
- ESP (AES-256) encrypts transaction data.
- Traffic Class = AF31 (DSCP 26) for high-priority payments.
- Flow Labels ensure low latency for real-time fraud detection.
5. IPv4/IPv6 Transition Security Risks
When networks run both IPv4 and IPv6, attackers exploit dual-stack vulnerabilities:
- IPv6 Leakage: Applications may leak IPv6 addresses (e.g., via WebRTC).
- Tunnel Misconfigurations: Teredo, 6to4, or ISATAP tunnels can be hijacked.
- Metadata Exposure: IPv6 traffic can reveal internal topology.
Mitigation Strategies:
- Disable IPv6 on unneeded interfaces (if not required).
- Use Firewall Rules to block unsolicited IPv6 traffic.
- Deploy SEND for ND security.
- Monitor with SIEM (e.g., Splunk) for suspicious IPv6 activity.
## In the real world
Ncell’s VoLTE Calls
- Idea Used: IPv6 Flow Labels + Traffic Class (EF)
- How: Each VoLTE call gets a unique Flow Label and DSCP 46 (EF) to ensure low latency and jitter-free audio. Without this, calls would drop during peak hours (e.g., 7–9 PM in Kathmandu).
eSewa’s Payment Security
- Idea Used: IPSec ESP (AES-256) + Traffic Class (AF31)
- How: When you transfer money via eSewa, the transaction packet is encrypted with ESP and marked with AF31 to bypass slower queues. If an attacker intercepts the packet, they cannot decrypt it without the pre-shared key.
YouTube’s Adaptive Streaming in Nepal
- Idea Used: Differentiated Services (Traffic Class)
- How: YouTube prioritizes video chunks (DSCP 46) over ads (DSCP 10). During Nepal’s monsoon season (when NTC links slow down), this ensures the video buffer doesn’t stall while ads load later.
## Exam Tip
Security Questions (30% weight):
- Must-know: IPSec AH vs. ESP, SEND, RA Guard.
- Common Pitfall: Confusing IPv4 IPSec (optional) with IPv6 IPSec (mandatory).
- Exam Trick: For ND attacks, always mention SEND + CGA as the solution.
QoS Questions (40% weight):
- Traffic Class vs. Flow Label:
- Traffic Class = Per-hop behavior (like DSCP in IPv4).
- Flow Label = End-to-end QoS (unique per flow).
- Worked Example: If asked about Ncell VoLTE, describe Flow Label + EF (DSCP 46).
- Traffic Class vs. Flow Label:
Transition Mechanisms (20% weight):
- 6to4 vs. Teredo: Know their security risks (e.g., 6to4 leaks IPs).
- Dual-Stack Risks: Always mention metadata exposure and firewall rules as mitigations.
Real-World Scenarios (10% weight):
- eSewa: IPSec ESP + Traffic Class.
- Ncell VoLTE: Flow Label + RSVPv6.
- NTC IPTV: AF41 for video, AF21 for menus.
Pro Tip: Draw IPv6 header diagrams (with AH/ESP/Traffic Class/Flow Label) in exams—they fetch extra marks for clarity.
Based on the TU BSc CSIT syllabus for Advanced Networking with IPv6, unit 4.
Discussion
Loading…