Method, device and electronic device for risk verification of IPv4 / IPv6 dual-stack network IPID policy defects

By carrying IPID in IPv6 communication packets and downgrading the IPID policy, using attack IPv6 addresses to detect sensitive information of IPv4/IPv6 dual-stack networks, the security risk of the failure of the existing technology to determine the defects of IPID policy is solved, and the risk verification of TCP bypass attacks is realized.

CN119583224BActive Publication Date: 2025-08-29北京建恒信安科技有限公司
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510134822.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-07
Publication Date
2025-08-29
Estimated Expiration
2045-02-07

AI Technical Summary

Technical Problem

The prior art cannot determine whether there is a security risk in IPID policy defects in IPv4/IPv6 dual-stack networks through TCP bypass attacks.

Method used

By carrying IPID in IPv6 communication packets and downgrading the IPID policy of the victim host to a 2048 hash counter strategy, using the attack IPv6 address to communicate with the victim host, detecting sensitive information of the IPv4/IPv6 dual-stack network, such as the source port number, the lower boundary of the reception window and the lower boundary of the sending window, to determine the security risks of IPID policy defects.

Benefits of technology

It is realized that the IPID policy defects in IPv4/IPv6 dual-stack networks are determined through TCP bypass attack method, which eases the limitations of traditional technologies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119583224B_ABST
    Figure CN119583224B_ABST
Patent Text Reader

Abstract

The present invention provides a risk verification method, device and electronic device for IPv4 / IPv6 dual-stack network IPID policy defects, belonging to the technical field of cyberspace security. In the method, the IPID policy of a victim host sending an IPv4 message to a victim client is downgraded, and then communication with the victim host is carried out by replacing the IPv6 address until an attacking IPv6 address that shares a hash IPID counter with the IPv4 address of the victim client is determined; then, when communicating with the victim host based on the attacking IPv6 address, sensitive information of the IPv4 / IPv6 dual-stack network is obtained according to the IPID detection carried in the segment extension header of the egress message, that is, it is possible to determine whether the IPID policy defect in the IPv4 / IPv6 dual-stack network has a security risk by means of a TCP bypass attack.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of cyberspace security, and in particular to a risk verification method, device, and electronic device for IPv4 / IPv6 dual-stack network IPID policy defects. Background Art

[0002] Currently, risk assessment for IPID policy flaws in IPv4 / IPv6 dual-stack networks is often conducted by determining whether the network is vulnerable to network attacks. If a network attack model is used to attack the IPID policy flaw in an IPv4 / IPv6 dual-stack network and sensitive information on the network is obtained, this indicates that the network is vulnerable to network attacks, further demonstrating that the IPID policy flaw in the IPv4 / IPv6 dual-stack network presents a security risk.

[0003] Traditional network attack models can be divided into attacks based on shared links (co-path and side-path models) and attacks based on malware implantation. In the traditional co-path (in-path) attack model, the attacker is located between the network paths of the communicating parties. They have the highest information resources and attack capabilities, and can sniff, intercept, tamper with, and forge communication traffic. In the traditional on-path model, the attacker controls a router or switch in the communication path between the two parties, able to sniff the packets flowing through that network device but unable to tamper with the packet content. In a malware implantation attack scenario, the attacker implants malware to steal information on the victim host. Even if the attacker does not have access to a shared link, the malware can still steal sensitive network connection information, such as providing command line information such as netstat to the attacker through the malware. However, in real networks, the prerequisites for remotely controlling communication links and pre-implanting malware are somewhat demanding for attackers, making the use of traditional attack models increasingly limited. There is an urgent need for new side-channel attacks that do not rely on shared links or malware implantation as prerequisites. In the new off-path attack model, the attacker is outside the network path between the communicating parties. They typically exploit vulnerabilities in the protocol stack to probe sensitive network connection information (such as randomized port numbers, TCP sequence numbers, and acknowledgment numbers). Compared to the two traditional models based on shared links, this off-path condition severely limits the attacker's information resources and attack capabilities, making traffic sniffing and packet tampering impossible. Therefore, the off-path attack model imposes low resource and zero capability constraints on the attacker, best simulating real-world network conditions and applicable to a wider range of attack and defense scenarios. In the malware-based attack model, all intelligence information used by the attacker to conduct infiltration is provided by pre-implanted malware. However, with the continuous development of intrusion detection and reverse attribution technology, the difficulty of implanting malware in real networks is increasing, and the attack behavior is easily exposed. The off-path attack model does not require the implantation of malware as a prerequisite for the attack, greatly lowering the threshold for launching the attack and effectively increasing the stealth of the attack.

[0004] In summary, how to obtain sensitive information of IPv4 / IPv6 dual-stack networks through TCP bypass attacks and then determine that the IPID policy defects in IPv4 / IPv6 dual-stack networks pose security risks has become a technical problem that urgently needs to be solved. Summary of the Invention

[0005] In view of this, the purpose of the present invention is to provide a risk verification method, device and electronic device for IPID policy defects in an IPv4 / IPv6 dual-stack network, so as to alleviate the technical problem that the existing technology cannot determine whether the IPID policy defects in the IPv4 / IPv6 dual-stack network pose a security risk through TCP bypass attacks.

[0006] In a first aspect, an embodiment of the present invention provides a risk verification method for IPv4 / IPv6 dual-stack network IPID policy defects, comprising:

[0007] When communicating with the victim host via an IPv6 communication message, causing the segment extension header of the egress message of the victim host to carry the IPID;

[0008] Downgrading the IPID policy used by the victim host to send IPv4 packets to the victim client to a 2048-hash counter policy, and then communicating with the victim host by changing the IPv6 address until an attacking IPv6 address that shares the same hash IPID counter as the victim client IPv4 address is determined;

[0009] When communicating with the victim host based on the attacking IPv6 address, detecting the source port number, the lower boundary of the receive window, and the lower boundary of the send window of the IPv4 TCP connection between the victim host and the victim client according to the IPID carried in the segment extension header of the egress message;

[0010] The source port number, the lower boundary of the receiving window and the lower boundary of the sending window are used as sensitive information of the IPv4 / IPv6 dual stack network, and it is determined that the IPID policy defect of the IPv4 / IPv6 dual stack network has the risk of TCP bypass attack.

[0011] Furthermore, when communicating with the victim host via an IPv6 communication message, the segment extension header of the egress message of the victim host carries the IPID, including:

[0012] Forging an ICMPv6 PacketTooBig message and sending it to the victim host, wherein the ICMPv6 PacketTooBig message carries a forged MTU value;

[0013] Constructing an ICMPv6 Echo Request message whose length is greater than the forged MTU value and sending it to the victim host;

[0014] The IPID is determined according to a segment extension header of an egress message of the victim host.

[0015] Furthermore, the IPID policy for the victim host to send IPv4 packets to the victim client is downgraded to a policy based on 2048 hash counters, including:

[0016] By impersonating the IPv4 address of the router in the communication path between the victim host and the victim client, a forged ICMP Fragmentation Needed message is sent to the victim host, so that the victim host uses a 2048 hash counter strategy to allocate an IPID for the IPv4 message sent to the victim client, wherein the forged ICMPFragmentation Needed message is used to indicate that the next-hop MTU value of the router between the victim host and the victim client is a preset value, and fragmentation of the egress message is not allowed.

[0017] Furthermore, when communicating with the victim host based on the attacking IPv6 address, detecting the source port number of the IPv4 TCP connection between the victim host and the victim client according to the IPID carried in the segment extension header of the egress message includes:

[0018] Send an IPv6 ICMP Echo Request message to the victim host using the attacking IPv6 address, and obtain the IPID carried in the fragment extension header of the corresponding egress message;

[0019] Using the IPv4 address of the victim client to send a forged SYN / ACK message with a guessed source port number to the victim host;

[0020] Continue to send IPv6 ICMP Echo Request messages to the victim host using the attacking IPv6 address, and obtain the IPID carried in the fragment extension header of the corresponding egress message;

[0021] Determining whether the guessed source port number is the source port number of the IPv4 TCP connection between the victim host and the victim client according to the change of the IPID, wherein the change of the IPID is the difference between the two most recently obtained IPIDs;

[0022] If the guessed source port number is not the source port number of the IPv4 TCP connection between the victim host and the victim client, a new guessed source port number is obtained, and the new guessed source port number is used as the guessed source port number, and the process returns to the step of sending a forged SYN / ACK message with the guessed source port number to the victim host by impersonating the IPv4 address of the victim client, until the guessed source port number is the source port number of the IPv4 TCP connection between the victim host and the victim client, thereby obtaining the source port number of the IPv4 TCP connection between the victim host and the victim client.

[0023] Furthermore, when communicating with the victim host based on the attacking IPv6 address, detecting the lower boundary of the receiving window and the lower boundary of the sending window according to the IPID carried in the segment extension header of the egress message includes:

[0024] Send an IPv6 ICMP Echo Request message to the victim host using the attacking IPv6 address, and obtain the IPID carried in the fragment extension header of the corresponding egress message;

[0025] Sending a forged RST message with a guessed sequence number to the victim host by impersonating the victim client's IPv4 address;

[0026] Continue to send IPv6 ICMP Echo Request messages to the victim host using the attacking IPv6 address, and obtain the IPID carried in the fragment extension header of the corresponding egress message;

[0027] Determining whether the guessed sequence number is an acceptable sequence number in the receiving window based on a change in the IPID, wherein the change in the IPID is a difference between two newly obtained IPIDs;

[0028] If the guessed sequence number is not an acceptable sequence number in the receive window, obtaining a new guessed sequence number and using the new guessed sequence number as the guessed sequence number, returning to the step of sending a forged RST message with the guessed sequence number to the victim host by impersonating the victim client's IPv4 address until the guessed sequence number is an acceptable sequence number in the receive window, thereby obtaining an acceptable sequence number in the receive window;

[0029] determining a challenge ACK window based on the acceptable sequence numbers;

[0030] The lower boundary of the receiving window and the lower boundary of the sending window are detected according to the acceptable sequence number and the challenge ACK window.

[0031] Further, determining a challenge ACK window based on the acceptable sequence number includes:

[0032] Send an IPv6 ICMP Echo Request message to the victim host using the attacking IPv6 address, and obtain the IPID carried in the fragment extension header of the corresponding egress message;

[0033] Sending a forged ACK message with a guessed ACK to the victim host by impersonating the victim client's IPv4 address;

[0034] Continue to send IPv6 ICMP Echo Request messages to the victim host using the attacking IPv6 address, and obtain the IPID carried in the fragment extension header of the corresponding egress message;

[0035] Determining whether the guessed ACK is within the challenge ACK window according to a change in the IPID, wherein the change in the IPID is a difference between two newly obtained IPIDs;

[0036] If the guessed ACK is within the challenge ACK window, determining the challenge ACK window according to the guessed ACK;

[0037] If the guessed ACK is not within the challenge ACK window, a new guessed ACK is obtained and used as the guessed ACK. The process returns to the step of sending a forged ACK message with the guessed ACK to the victim host by impersonating the victim client's IPv4 address until the guessed ACK is within the challenge ACK window, and the challenge ACK window is then determined based on the guessed ACK finally obtained.

[0038] Further, detecting the lower boundary of the receiving window and the lower boundary of the sending window according to the acceptable sequence number and the challenge ACK window includes:

[0039] Send an IPv6 ICMP Echo Request message to the victim host using the attacking IPv6 address, and obtain the IPID carried in the fragment extension header of the corresponding egress message;

[0040] Sending a forged ACK message to the victim host by impersonating the victim client IPv4 address, wherein the ACK is a preset ACK in the challenge ACK window and the sequence number is a current sequence number determined according to the acceptable sequence number;

[0041] Continue to send IPv6 ICMP Echo Request messages to the victim host using the attacking IPv6 address, and obtain the IPID carried in the fragment extension header of the corresponding egress message;

[0042] Determining whether the current sequence number is the lower boundary of the receiving window according to the frequency jitter of the obtained IPID;

[0043] If the current sequence number is not the lower boundary of the receive window, determining a new sequence number based on the acceptable sequence number, and using the new sequence number as the current sequence number determined based on the acceptable sequence number, returning to the step of using the victim client's IPv4 address to send a forged ACK message to the victim host, where the ACK is a preset ACK in the challenge ACK window and the sequence number is the current sequence number determined based on the acceptable sequence number, until the current sequence number is the lower boundary of the receive window, thereby obtaining the lower boundary of the receive window;

[0044] Send an IPv6 ICMP Echo Request message to the victim host using the attacking IPv6 address, and obtain the IPID carried in the fragment extension header of the corresponding egress message;

[0045] Using the IPv4 address of the victim client to send a forged ACK message to the victim host, wherein the sequence number is a preset sequence number above the lower boundary of the receiving window and the ACK is a current ACK determined according to the preset ACK;

[0046] Continue to send IPv6 ICMP Echo Request messages to the victim host using the attacking IPv6 address, and obtain the IPID carried in the fragment extension header of the corresponding egress message;

[0047] Determining whether the current ACK is the lower boundary of the sending window according to the frequency jitter of the obtained IPID;

[0048] If the current ACK is not the lower boundary of the sending window, a new ACK is determined based on the preset ACK, and the new ACK is used as the current ACK determined based on the preset ACK. The process returns to the step of using the victim client's IPv4 address to send a forged ACK message to the victim host, with a sequence number that is a preset sequence number above the lower boundary of the receiving window and an ACK that is the current ACK determined based on the preset ACK, until the current ACK is the lower boundary of the sending window, thereby obtaining the lower boundary of the sending window.

[0049] In a second aspect, an embodiment of the present invention further provides a risk verification device for IPv4 / IPv6 dual-stack network IPID policy defects, comprising:

[0050] An IPID acquiring unit, configured to, when communicating with a victim host via an IPv6 communication message, cause the segment extension header of an egress message of the victim host to carry the IPID;

[0051] a downgrading and determining unit, configured to downgrade the IPID policy for the victim host to send IPv4 packets to the victim client to a policy based on 2048 hash counters, and then communicate with the victim host by changing the IPv6 address until an attacking IPv6 address that shares the same hash IPID counter with the victim client IPv4 address is determined;

[0052] a detection unit, configured to detect, when communicating with the victim host based on the attacking IPv6 address, the source port number, the lower boundary of the receive window, and the lower boundary of the send window of the IPv4 TCP connection between the victim host and the victim client according to the IPID carried in the segment extension header of the egress message;

[0053] A setting and determination unit is used to use the source port number, the lower boundary of the receiving window and the lower boundary of the sending window as sensitive information of the IPv4 / IPv6 dual stack network, and determine that the IPID policy defect of the IPv4 / IPv6 dual stack network has the risk of TCP bypass attack.

[0054] In a third aspect, an embodiment of the present invention further provides an electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of any one of the methods described in the first aspect when executing the computer program.

[0055] In a fourth aspect, an embodiment of the present invention further provides a computer-readable storage medium, wherein the computer-readable storage medium stores machine-executable instructions. When the machine-executable instructions are called and executed by a processor, the machine-executable instructions prompt the processor to execute any method described in the first aspect above.

[0056] In an embodiment of the present invention, a risk verification method for an IPv4 / IPv6 dual-stack network IPID policy defect is provided, comprising: when communicating with a victim host via an IPv6 communication message, causing the segment extension header of the victim host's egress message to carry an IPID; downgrading the IPID policy for the victim host to send IPv4 messages to a victim client to a policy based on 2048 hash counters, and then communicating with the victim host by replacing the IPv6 address until an attacking IPv6 address that shares a hash IPID counter with the victim client's IPv4 address is determined; when communicating with the victim host based on the attacking IPv6 address, detecting the source port number, the lower boundary of the receive window, and the lower boundary of the send window of the IPv4 TCP connection between the victim host and the victim client based on the IPID carried in the segment extension header of the egress message; using the source port number, the lower boundary of the receive window, and the lower boundary of the send window as sensitive information of the IPv4 / IPv6 dual-stack network, and determining that the IPID policy defect of the IPv4 / IPv6 dual-stack network presents a risk of a TCP bypass attack. From the above description, it can be seen that in the risk verification method of the IPv4 / IPv6 dual-stack network IPID policy defect of the present invention, the IPID policy of the victim host sending the IPv4 message to the victim client is downgraded, and then the attack IPv6 address is replaced by the victim host to communicate until the attack IPv6 address that shares the hash IPID counter with the victim client IPv4 address is determined; then, when communicating with the victim host based on the attack IPv6 address, the sensitive information of the IPv4 / IPv6 dual-stack network is obtained according to the IPID detection carried in the segment extension header of the export message, that is, it is possible to determine whether the IPID policy defect in the IPv4 / IPv6 dual-stack network has a security risk by means of a TCP bypass attack, thereby alleviating the technical problem that the traditional technology cannot determine whether the IPID policy defect in the IPv4 / IPv6 dual-stack network has a security risk by means of a TCP bypass attack. BRIEF DESCRIPTION OF THE DRAWINGS

[0057] In order to more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the specific embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0058] Figure 1 A flowchart of a risk verification method for an IPv4 / IPv6 dual-stack network IPID policy defect provided by an embodiment of the present invention;

[0059] Figure 2A schematic diagram comparing IPv4 and IPv6 datagram headers provided in an embodiment of the present invention;

[0060] Figure 3 A schematic diagram of an ICMPv6 PacketTooBig message forged by an attacker according to an embodiment of the present invention;

[0061] Figure 4 A schematic diagram of an attacker obtaining an IPID from an IPv6 fragment extension header of a victim host according to an embodiment of the present invention;

[0062] Figure 5 A schematic diagram of an embodiment of the present invention providing an IPID with no additional increment when detecting a source port;

[0063] Figure 6 A schematic diagram illustrating an additional increment in the IPID when detecting a source port according to an embodiment of the present invention;

[0064] Figure 7 A schematic diagram of an embodiment of the present invention providing an example of detecting an acceptable sequence number without an additional increment of the IPID;

[0065] Figure 8 A schematic diagram illustrating an additional increment of the IPID when detecting an acceptable sequence number according to an embodiment of the present invention;

[0066] Figure 9 A schematic diagram illustrating an additional increment of IPID when determining a challenge ACK window according to an embodiment of the present invention;

[0067] Figure 10 A schematic diagram of determining a challenge ACK window without an additional increment of IPID according to an embodiment of the present invention;

[0068] Figure 11 A schematic diagram of a risk verification device for an IPv4 / IPv6 dual-stack network IPID policy defect provided by an embodiment of the present invention;

[0069] Figure 12 A schematic diagram of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0070] The following will clearly and completely describe the technical solutions of the present invention in conjunction with the embodiments. Obviously, the embodiments described are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0071] Traditional technologies cannot determine whether IPID policy defects in IPv4 / IPv6 dual-stack networks pose security risks through TCP bypass attacks.

[0072] Based on this, in the risk verification method of the IPv4 / IPv6 dual-stack network IPID policy defect of the present invention, the IPID policy of the victim host sending IPv4 messages to the victim client is downgraded, and then communication with the victim host is carried out by changing the IPv6 address until the attack IPv6 address that shares the hash IPID counter with the victim client IPv4 address is determined; then, when communicating with the victim host based on the attack IPv6 address, sensitive information of the IPv4 / IPv6 dual-stack network is obtained according to the IPID detection carried in the segment extension header of the outbound message, that is, it is possible to determine whether there is a security risk in the IPID policy defect in the IPv4 / IPv6 dual-stack network by means of a TCP bypass attack.

[0073] To facilitate understanding of this embodiment, a risk verification method for an IPv4 / IPv6 dual-stack network IPID policy defect disclosed in an embodiment of the present invention is first introduced in detail.

[0074] Example 1:

[0075] According to an embodiment of the present invention, an embodiment of a risk verification method for IPID policy defects in an IPv4 / IPv6 dual-stack network is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.

[0076] Figure 1 Flowchart of a risk verification method for an IPv4 / IPv6 dual stack network IPID policy defect according to an embodiment of the present invention. Figure 1 As shown, the method includes the following steps:

[0077] Step S102, when communicating with the victim host via IPv6 communication messages, the segment extension header of the victim host's egress message carries the IPID;

[0078] In an embodiment of the present invention, the risk verification method for IPv4 / IPv6 dual-stack network IPID policy defects can be applied to an attacker, specifically a host used for attack, and the egress message specifically refers to a message sent by the victim host.

[0079] In IPv4, IP datagrams carry an IPID field (identification) in their header by default. An attacker can send an ICMPv4 Request message to a victim host and observe the IPID field in the ICMPv4 Reply message (i.e., the egress message) returned by the victim host. However, in IPv6, the IPv6 datagram header format is simplified. The header no longer contains the IPID field, but is placed in an extension header, such as Figure 2 As shown in the figure, IPv6 can only carry an IPID if it carries the Fragment extension header. Therefore, the victim host must fragment the packets it sends to the attacker (i.e., the outbound packets) to obtain the IPID assigned by the victim host. In other words, when communicating with the victim host via IPv6, the attacker must ensure that the Fragment extension header in the outbound packets sent by the victim host carries the IPID. This allows the attacker to obtain the IPID after receiving the Fragment extension header. This process is described in detail below and will not be repeated here.

[0080] Step S104: Downgrade the IPID policy used by the victim host to send IPv4 packets to the victim client to a policy based on 2048 hash counters, and then communicate with the victim host by changing the IPv6 address until an attacking IPv6 address that shares the same hash IPID counter as the victim client IPv4 address is determined.

[0081] Specifically, the original IPID policy for the victim host to send IPv4 packets to the victim client is a socket-based policy, which is relatively secure. Therefore, the original policy needs to be downgraded to a less secure policy based on 2048 hash counters. In this way, subsequent communication with the victim host can be carried out by changing the IPv6 address, and then the attacking IPv6 address that shares the hash IPID counter with the victim client IPv4 address can be determined.

[0082] The following describes the process of determining the attacking IPv6 address:

[0083] Based on this knowledge of the hashing algorithm, the attacker begins generating a series of different IPv6 addresses and attempts to use them to communicate with the victim host. Each new IPv6 address represents an attempt to find an attacking IPv6 address that results in the same hash result as the victim client's IPv4 address. For each generated IPv6 address, the attacker sends one or more probe packets to the victim host. These packets are typically very small data transfer requests designed to trigger a response from the victim host and the assignment of a new IPID value. The attacker carefully monitors the IPID value in the response packets sent back from the victim host. If data packets from two different sources (i.e., the attacker's IPv6 address and the victim's IPv4 address) are assigned consecutive or very close IPID values, then it is determined that the two addresses (i.e., the attacker's IPv6 address and the victim's IPv4 address at this time) share the same hash IPID counter. The IPv6 address at this time is the attacking IPv6 address. When the attacking IPv6 address communicates with the victim host via IPv6, the IPID in the egress message returned by the victim host is the IPID when the victim client communicated with the victim host via IPv4. In other words, the communication between the attacker's attacking IPv6 address and the victim host reflects the communication between the victim client and the victim host, thus achieving a TCP bypass attack.

[0084] Step S106, when communicating with the victim host based on the attacking IPv6 address, detecting the source port number, the lower boundary of the receiving window, and the lower boundary of the sending window of the IPv4 TCP connection between the victim host and the victim client according to the IPID carried in the segment extension header of the outgoing message;

[0085] Step S108 : The source port number, the lower boundary of the receiving window, and the lower boundary of the sending window are used as sensitive information of the IPv4 / IPv6 dual stack network, and it is determined that the IPID policy defect of the IPv4 / IPv6 dual stack network has the risk of TCP bypass attack.

[0086] In an embodiment of the present invention, a risk verification method for an IPv4 / IPv6 dual-stack network IPID policy defect is provided, comprising: when communicating with a victim host via an IPv6 communication message, causing the segment extension header of the victim host's egress message to carry an IPID; downgrading the IPID policy for the victim host to send IPv4 messages to a victim client to a policy based on 2048 hash counters, and then communicating with the victim host by replacing the IPv6 address until an attacking IPv6 address that shares a hash IPID counter with the victim client's IPv4 address is determined; when communicating with the victim host based on the attacking IPv6 address, detecting the source port number, the lower boundary of the receive window, and the lower boundary of the send window of the IPv4 TCP connection between the victim host and the victim client based on the IPID carried in the segment extension header of the egress message; using the source port number, the lower boundary of the receive window, and the lower boundary of the send window as sensitive information of the IPv4 / IPv6 dual-stack network, and determining that the IPID policy defect of the IPv4 / IPv6 dual-stack network presents a risk of a TCP bypass attack. From the above description, it can be seen that in the risk verification method of the IPv4 / IPv6 dual-stack network IPID policy defect of the present invention, the IPID policy of the victim host sending the IPv4 message to the victim client is downgraded, and then the attack IPv6 address is replaced by the victim host to communicate until the attack IPv6 address that shares the hash IPID counter with the victim client IPv4 address is determined; then, when communicating with the victim host based on the attack IPv6 address, the sensitive information of the IPv4 / IPv6 dual-stack network is obtained according to the IPID detection carried in the segment extension header of the export message, that is, it is possible to determine whether the IPID policy defect in the IPv4 / IPv6 dual-stack network has a security risk by means of a TCP bypass attack, thereby alleviating the technical problem that the traditional technology cannot determine whether the IPID policy defect in the IPv4 / IPv6 dual-stack network has a security risk by means of a TCP bypass attack.

[0087] The above content briefly introduces the risk verification method for IPv4 / IPv6 dual-stack network IPID policy defects of the present invention. The specific contents involved are described in detail below.

[0088] In an optional embodiment of the present invention, when communicating with a victim host via an IPv6 communication message, the segment extension header of the victim host's egress message carries the IPID, specifically comprising the following steps:

[0089] (1) Forge an ICMPv6 PacketTooBig message and send it to the victim host. The ICMPv6 PacketTooBig message carries a forged MTU value.

[0090] Specifically, the attacker forges an ICMPv6 PacketTooBig message and sends it to the victim host. The forged message is as follows: Figure 3 As shown in the figure, forge_ip is the attacker's IPv6 address, server_ip is the victim's IPv6 address, and MTU is the attacker's modified MTU value. According to the IPv6 protocol standard and the Linux kernel implementation, an attacker can modify the MTU field to a minimum of 1280 bytes.

[0091] (2) Construct an ICMPv6 Echo Request message whose length is greater than the forged MTU value and send it to the victim host;

[0092] Specifically, the attacker constructs a length greater than fake_MTU (forged MTU value, according to Figure 3 The attacker then sends an ICMPv6 Echo Request message (larger than 1280 bytes in this example) to the victim. The victim then responds with a fragmented ICMPv6 Echo Reply (i.e., the egress message) to the attacker, with the fragment extension header carrying the IPID.

[0093] (3) Determine the IPID based on the segment extension header of the victim host's outbound message.

[0094] Specifically, the above process is as follows Figure 4 shown.

[0095] In an optional embodiment of the present invention, the IPID policy for the victim host to send IPv4 packets to the victim client is downgraded to a policy based on 2048 hash counters, specifically comprising the following steps:

[0096] The IPv4 address of the router in the communication path between the victim host and the victim client is impersonated, and a forged ICMP Fragmentation Needed message is sent to the victim host, causing the victim host to use a 2048 hash counter strategy to allocate an IPID for the IPv4 message sent to the victim client. The forged ICMP Fragmentation Needed message is used to indicate that the next-hop MTU value of the router between the victim host and the victim client is a preset value, and fragmentation of the outbound message is not allowed.

[0097] Specifically, the above preset value is a smaller value. To implement this, the attacker forges an ICMP message: they send a forged ICMP "Fragmentation Needed" message to the victim host, claiming that a router along the path has a smaller next-hop MTU and disallows packet fragmentation. They also change the IPID generation strategy: if the victim host believes this message and believes fragmentation must be avoided, it may use a simpler hash counter strategy to assign IPIDs to outgoing packets, rather than a more random method. This achieves IPID policy downgrade.

[0098] In an optional embodiment of the present invention, when communicating with a victim host based on an attacking IPv6 address, detecting the source port number of the IPv4 TCP connection between the victim host and the victim client based on the IPID carried in the segment extension header of the outgoing message specifically includes the following steps:

[0099] (1) Send an IPv6 ICMP Echo Request message to the victim host using the attacking IPv6 address and obtain the IPID carried in the fragment extension header of the corresponding outgoing message;

[0100] (2) Using the victim client's IPv4 address to send a forged SYN / ACK message with a guessed source port number to the victim host;

[0101] (3) Continue to send IPv6 ICMP Echo Request messages to the victim host using the attacking IPv6 address, and obtain the IPID carried in the fragment extension header of the corresponding outgoing message;

[0102] (4) Determine whether the guessed source port number is the source port number of the IPv4 TCP connection between the victim host and the victim client based on the change in IPID, where the change in IPID is the difference between the two most recently obtained IPIDs;

[0103] Specifically, if the IPID change is 1, it is determined that the guessed source port number is not the source port number of the IPv4 TCP connection between the victim host and the victim client; if the IPID change is 2, it is determined that the guessed source port number is the source port number of the IPv4 TCP connection between the victim host and the victim client.

[0104] (5) If the guessed source port number is not the source port number of the IPv4 TCP connection between the victim host and the victim client, a new guessed source port number is obtained and used as the guessed source port number, and the process returns to the step of sending a forged SYN / ACK message with the guessed source port number to the victim host by impersonating the victim client's IPv4 address, until the guessed source port number is the source port number of the IPv4 TCP connection between the victim host and the victim client, thereby obtaining the source port number of the IPv4 TCP connection between the victim host and the victim client.

[0105] Specifically, assuming that the victim client has established a TCP connection with the victim host using source port number m, the attacker can send a probe message to determine the source port number.

[0106] First, the attacker continuously sends IPv6 ICMP Echo Request messages to the victim host using the attacking IPv6 address, and observes the IPID value in the ICMP reply message (i.e., the outgoing message) segment extension header. Then, the attacker uses the victim client's IPv4 address to send a forged SYN / ACK message with a guessed source port number n to the victim host. If the guessed port number n is not equal to m, according to the TCP specification, the victim host will send a RST message back to the victim client. Since Linux kernel 4.18 and above assigns an IPID of 0 to the RST message, it will not cause the hashed IPID counter to increase. Therefore, the IPIDs observed by the attacker from the ICMPv6 Echo Reply message segment extension header are continuous, such as Figure 5 .

[0107] If the source port number specified in the forged SYN / ACK message is exactly m, the challenge ACK mechanism causes the victim host to send a challenge ACK message to the victim client to confirm the legitimacy of the forged SYN / ACK message. The challenge ACK message will assign a hash IPID counter, causing the hash IPID counter to increase. Therefore, from the attacker's perspective, the IPIDs of the ICMPv6 EchoReply reply messages will be discontinuous, such as Figure 6 The attacker repeats the above steps, constantly modifying the source port number in the forged SYN / ACK message and observing the IPID in the ICMP reply message until the correct source port m is determined.

[0108] In an optional embodiment of the present invention, when communicating with a victim host based on an attacking IPv6 address, detecting the lower boundary of the receiving window and the lower boundary of the sending window according to the IPID carried in the segment extension header of the egress message specifically includes the following steps:

[0109] (1) Send an IPv6 ICMP Echo Request message to the victim host using the attacking IPv6 address and obtain the IPID carried in the fragment extension header of the corresponding outgoing message;

[0110] (2) Using the victim client's IPv4 address to send a forged RST message with a guessed sequence number to the victim host;

[0111] (3) Continue to send IPv6 ICMP Echo Request messages to the victim host using the attacking IPv6 address, and obtain the IPID carried in the fragment extension header of the corresponding outgoing message;

[0112] (4) Determine whether the guessed sequence number is an acceptable sequence number in the receiving window based on the change in IPID, where the change in IPID is the difference between the two most recently obtained IPIDs;

[0113] Specifically, if the change in the IPID is 1, it is determined that the guessed sequence number is not an acceptable sequence number in the receiving window; if the change in the IPID is 2, it is determined that the guessed sequence number is an acceptable sequence number in the receiving window.

[0114] (5) If the guessed sequence number is not an acceptable sequence number in the receive window, a new guessed sequence number is obtained and used as the guessed sequence number, and the process returns to the step of sending a forged RST message with the guessed sequence number to the victim host using the victim client's IPv4 address until the guessed sequence number is an acceptable sequence number in the receive window, thereby obtaining an acceptable sequence number in the receive window.

[0115] Specifically, in order to infer the acceptable sequence number in the victim host's receiving window, the attacker continuously sends IPv6 ICMP Echo Request messages to the victim host using the attacking IPv6 address and observes the replying IPID; then, the attacker uses the victim client's IPv4 address to send a forged RST message with the guessed sequence number seq to the victim host. There are two cases to consider: ① seq is not in the victim host's receiving window; ② seq is in the victim host's receiving window. In the first case, the victim host will directly discard the forged RST message, which will not affect the hashed IPID counter, such as Figure 7 .

[0116] In the second case, the victim host sends a challenge ACK message to the victim client to verify the legitimacy of the RST message. This challenge ACK message will assign a hash IPID counter, causing the counter to increase additionally, such as Figure 8The attacker can observe this increase and determine whether the guessed sequence number seq is within the receiving window of the victim host, thereby obtaining the acceptable sequence number within the receiving window.

[0117] (6) Determine the challenge ACK window based on the acceptable sequence number;

[0118] The specific steps include:

[0119] (61) Send an IPv6 ICMP Echo Request message to the victim host using the attacking IPv6 address, and obtain the IPID carried in the fragment extension header of the corresponding outgoing message;

[0120] (62) Using the victim client's IPv4 address to send a forged ACK message with a guessed ACK to the victim host;

[0121] (63) Continue to send IPv6 ICMP Echo Request messages to the victim host using the attacking IPv6 address, and obtain the IPID carried in the fragment extension header of the corresponding outgoing message;

[0122] (64) Determine whether the guessed ACK is within the challenge ACK window based on the change in IPID, where the change in IPID is the difference between the two most recently obtained IPIDs;

[0123] Specifically, if the change in the IPID is 1, it is determined that the guessed ACK is not within the challenge ACK window; if the change in the IPID is 2, it is determined that the guessed ACK is within the challenge ACK window.

[0124] (65) If the guessed ACK is within the challenge ACK window, the challenge ACK window is determined based on the guessed ACK;

[0125] (66) If the guessed ACK is not within the challenge ACK window, a new guessed ACK is obtained and used as the guessed ACK, and the process returns to the step of sending a forged ACK message with the guessed ACK to the victim host by impersonating the victim client's IPv4 address until the guessed ACK is within the challenge ACK window, and then the challenge ACK window is determined based on the guessed ACK finally obtained.

[0126] Specifically, according to the TCP standard RFC 5961, when a TCP segment (including Figure 9When an ACK in the trigger segment arrives at the victim host, even if its sequence number seq is within the victim host's receive window, the ACK number will be checked. In the entire ACK number space, there are three cases: ① the ACK number in the challenge ACK window, and further determine the challenge ACK window based on the ACK number; ② within the acceptable ACK range; ③ invalid ACK number. In the first case, the victim host will send a challenge ACK packet to confirm the legitimacy of the trigger segment, such as Figure 9 In the second case, the victim host will directly accept the segment. In the third case, if the segment carries an invalid ACK, the victim host will directly discard it. The latter two cases cannot be directly distinguished, such as Figure 10 , because it cannot be observed from an off-path attacker. However, the attacker can first identify the server's challenge ACK window based on the following.

[0127] When locating the Challenge ACK window, the attacker observes and records the hashed IPID counter. The attacker then impersonates the victim client and sends a forged ACK packet to the victim host with a guessed ACK number. This forged ACK also specifies the previously detected acceptable sequence number. If the ACK falls within the Challenge ACK window, a Challenge ACK packet is sent, causing the hashed IPID counter to increment. Conversely, if the ACK falls outside the Challenge ACK window, the observed IPIDs will appear consecutive from the attacker's perspective. In practice, the Challenge ACK window size is always between 1G and 2G, which is one-quarter of the entire ACK number space (the total ACK number space is 4G). Therefore, to facilitate detection, the attacker can divide the entire space into four blocks (0G and 1G, 1G and 2G, 2G and 3G, and 3G and 4G) and probe each block (using a guessed ACK from each block to forge an ACK packet) to determine which block the Challenge ACK window falls into.

[0128] For example, if the guessed ACK 0.8G is within the challenge ACK window, then the challenge ACK window can be determined to be 0G and 1G; if the guessed ACK 1.2G is within the challenge ACK window, then the challenge ACK window can be determined to be 1G and 2G.

[0129] (7) Detect the lower boundary of the receive window and the lower boundary of the send window based on the acceptable sequence number and the challenge ACK window.

[0130] The specific steps include:

[0131] (71) Send an IPv6 ICMP Echo Request message to the victim host using the attacking IPv6 address, and obtain the IPID carried in the fragment extension header of the corresponding outgoing message;

[0132] (72) Using the victim client's IPv4 address to send a forged ACK message to the victim host, with the ACK being the preset ACK in the challenge ACK window and the sequence number being the current sequence number determined based on the acceptable sequence number;

[0133] Specifically, the current sequence number is an acceptable sequence number that is gradually decreased in steps of 1. The first current sequence number is the acceptable sequence number - 1, the second current sequence number is the acceptable sequence number - 2, and so on.

[0134] (73) Continue to send IPv6 ICMP Echo Request messages to the victim host using the attacking IPv6 address, and obtain the IPID carried in the fragment extension header of the corresponding outgoing message;

[0135] (74) Determine whether the current sequence number is the lower boundary of the receiving window based on the frequency jitter of the obtained IPID;

[0136] Specifically, if the frequency jitter of the IPID does not change, it is determined that the current sequence number is not the lower boundary of the receiving window; if the frequency jitter of the IPID changes, it is determined that the current sequence number is the lower boundary of the receiving window.

[0137] (75) If the current sequence number is not the lower boundary of the receive window, a new sequence number is determined based on the acceptable sequence number, and the new sequence number is used as the current sequence number determined based on the acceptable sequence number, and the process returns to the step of using the victim client's IPv4 address to send a forged ACK message to the victim host, where the ACK is the preset ACK in the challenge ACK window and the sequence number is the current sequence number determined based on the acceptable sequence number, until the current sequence number is the lower boundary of the receive window, thereby obtaining the lower boundary of the receive window;

[0138] (76) Send an IPv6 ICMP Echo Request message to the victim host using the attacking IPv6 address, and obtain the IPID carried in the fragment extension header of the corresponding outgoing message;

[0139] (77) Using the victim client's IPv4 address to send a forged ACK message to the victim host, with the sequence number being a preset sequence number above the lower boundary of the receiving window and the ACK being the current ACK determined based on the preset ACK;

[0140] (78) Continue to send IPv6 ICMP Echo Request messages to the victim host using the attacking IPv6 address, and obtain the IPID carried in the fragment extension header of the corresponding outgoing message;

[0141] (79) Determine whether the current ACK is the lower boundary of the sending window based on the frequency jitter of the obtained IPID;

[0142] (80) If the current ACK is not the lower boundary of the sending window, a new ACK is determined based on the preset ACK, and the new ACK is used as the current ACK determined based on the preset ACK. The process returns to the step of using the victim client's IPv4 address to send a forged ACK message to the victim host, with the sequence number being a preset sequence number above the lower boundary of the receiving window and the ACK being the current ACK determined based on the preset ACK, until the current ACK is the lower boundary of the sending window, thereby obtaining the lower boundary of the sending window.

[0143] Specifically, the attacker detects the exact sequence number (i.e., RCV.NXT, the lower boundary of the victim host's receive window) based on the previously inferred results. Within the challenge ACK window, the attacker forges multiple forged ACK messages with the acknowledgment number ack_challenge (i.e., ACK) set to a constant (i.e., a preset ACK). The attacker sets the sequence number (i.e., the current sequence number) specified in each forged ACK message to seq_acceptable (i.e., the acceptable sequence number) - i (this determines the current sequence number based on the acceptable sequence number, effectively decreasing the acceptable sequence number by steps of 1. For example, if the acceptable sequence number is 150, the current sequence number is 149, 148, 147, 146, and so on), where seq_acceptable is the previously inferred acceptable sequence number. The attacker then impersonates the victim client's IPv4 address and sends these forged ACK messages to the victim host. Initially, due to the rate limit on challenge ACKs, the victim will be triggered to send challenge ACK packets at a rate of one packet every 500 milliseconds. Therefore, the triggered challenge ACK packets will cause the hashed IPID counter to regularly increment. However, once the specified sequence number seq_acceptable (i.e., the current sequence number) reaches RCV.NXT (the lower boundary of the victim's receive window), the victim will switch to sending repeated ACK packets, unaffected by any rate limit. As a result, the hashed IPID counter will experience jitter, which the attacker can observe and then detect whether the current sequence number is at the lower boundary of the receive window.

[0144] Once the challenge ACK window is determined, the attacker can also send multiple forged ACK packets and then observe the hashed IPID counter to detect the lower boundary of the challenge ACK window (i.e., the lower boundary of the send window), similar to detecting the lower boundary of the victim's receive window. The forged ACK packets are designated with a constant sequence number, seq_acceptable (i.e., a fixed sequence number above the lower boundary of the receive window), and the acknowledgment number of each forged ACK packet is set to ack_challenge (an ACK in the challenge ACK window, such as the preset ACK mentioned above) - i (i.e., the current ACK is determined based on the preset ACK, which is actually a gradual decrement of the preset ACK in a certain step). The attacker then sends these forged ACK packets to the victim. Challenge ACK packets will be triggered until ack_challenge - i reaches the lower boundary of the challenge ACK window (i.e., the lower boundary of the send window). Once this boundary is detected, SND.UNA (i.e., the upper boundary of the send window) can be easily inferred, that is, the upper boundary of the send window is the detected lower boundary of the send window plus 2G (the process of determining the lower boundary of the send window is similar to the process of determining the lower boundary of the receive window mentioned above, and will not be elaborated here).

[0145] The present invention provides a method for finding a target TCP connection for a side channel attack when network message sniffing and tampering are impossible. The main principle is to utilize the IPID allocation strategy and TCP Challenge ACK mechanism in the Linux kernel to assign different patterns of IPIDs to outgoing messages when responding to different types of messages (whether the sequence number and acknowledgment number of the incoming TCP message are legitimate or not) under different circumstances (whether the DF flag is in the zero position or not). This outgoing message IPID pattern is used as a side channel to help attackers infer sensitive information such as the source port, TCP sequence number (specifically, the lower boundary of the receive window), and acknowledgment number (specifically, the lower boundary of the send window) of the target TCP connection.

[0146] This paper demonstrates the results of an attacker attacking a target's TCP by exploiting IPv6 address conflicts (i.e., obtaining sensitive information on an IPv4 / IPv6 dual-stack network). When tested using the application layer protocol HTTP, a bypass attacker can infer the IPv4 address, source port number, and sequence and acknowledgment numbers of the victim client connecting to the web server (i.e., the victim host). This confirms that the IPID policy flaw in IPv4 / IPv6 dual-stack networks presents a risk of TCP bypass attacks.

[0147] The above process involves three hosts. The web server (i.e., the victim host) is equipped with a Linux 4.18 operating system and starts the HTTP server. The client (i.e., the victim client) can access the web server based on HTTP. The attacking machine (i.e., the attacker, the host used for attack) is equipped with Ubuntu 18.04 (kernel version 4.18) and is able to send data packets to the server using a spoofed IP address. The attacker attempts to identify potential victim clients and hijack the TCP connection between the server and the client. It should be mentioned that the attacker knows the IPv4 and IPv6 addresses of the server and the HTTP port number opened by the server. The method of the present invention is applicable to various network architectures in IPv4 / IPv6 dual-stack networks, including: private LANs, the public Internet, and multi-level network environments with complex routing mechanisms.

[0148] Example 2:

[0149] An embodiment of the present invention also provides a risk verification device for IPv4 / IPv6 dual-stack network IPID policy defects. The risk verification device for IPv4 / IPv6 dual-stack network IPID policy defects is mainly used to execute the risk verification method for IPv4 / IPv6 dual-stack network IPID policy defects provided in the first embodiment of the present invention. The following is a detailed introduction to the risk verification device for IPv4 / IPv6 dual-stack network IPID policy defects provided by the embodiment of the present invention.

[0150] Figure 11 Schematic diagram of a risk verification device for an IPv4 / IPv6 dual stack network IPID policy defect according to an embodiment of the present invention. Figure 11 As shown, the device mainly includes: an IPID acquisition unit 10, a degradation and determination unit 20, a detection unit 30, and a setting and determination unit 40, wherein:

[0151] An IPID obtaining unit is configured to, when communicating with a victim host via an IPv6 communication message, cause the segment extension header of an egress message of the victim host to carry the IPID;

[0152] a downgrading and determining unit, configured to downgrade the IPID policy for the victim host to send IPv4 packets to the victim client to a policy based on 2048 hash counters, and then communicate with the victim host by changing the IPv6 address until an attacking IPv6 address that shares the same hash IPID counter with the victim client IPv4 address is determined;

[0153] a detection unit, configured to detect, when communicating with a victim host based on the attacking IPv6 address, the source port number, the lower boundary of the receiving window, and the lower boundary of the sending window of the IPv4 TCP connection between the victim host and the victim client according to the IPID carried in the segment extension header of the outgoing message;

[0154] The setting and determining unit is used to use the source port number, the lower boundary of the receiving window and the lower boundary of the sending window as sensitive information of the IPv4 / IPv6 dual stack network, and determine that the IPID policy defect of the IPv4 / IPv6 dual stack network has the risk of TCP bypass attack.

[0155] In an embodiment of the present invention, a risk verification device for an IPv4 / IPv6 dual-stack network IPID policy defect is provided, comprising: when communicating with a victim host via an IPv6 communication message, causing the segment extension header of the victim host's outbound message to carry an IPID; downgrading the IPID policy for the victim host to send IPv4 messages to a victim client to a policy based on 2048 hash counters, and then communicating with the victim host by changing the IPv6 address until an attacking IPv6 address that shares a hash IPID counter with the victim client's IPv4 address is determined; when communicating with the victim host based on the attacking IPv6 address, detecting the source port number, the lower boundary of the receive window, and the lower boundary of the send window of the IPv4 TCP connection between the victim host and the victim client based on the IPID carried in the segment extension header of the outbound message; using the source port number, the lower boundary of the receive window, and the lower boundary of the send window as sensitive information of the IPv4 / IPv6 dual-stack network, and determining that the IPID policy defect of the IPv4 / IPv6 dual-stack network presents a risk of TCP bypass attack. From the above description, it can be seen that in the risk verification device for IPv4 / IPv6 dual-stack network IPID policy defects of the present invention, the IPID policy of the victim host sending IPv4 messages to the victim client is downgraded, and then communication with the victim host is carried out by changing the IPv6 address until the attack IPv6 address that shares the hash IPID counter with the victim client IPv4 address is determined; then, when communicating with the victim host based on the attack IPv6 address, sensitive information of the IPv4 / IPv6 dual-stack network is obtained according to the IPID detection carried in the segment extension header of the export message, that is, it is possible to determine whether the IPID policy defect in the IPv4 / IPv6 dual-stack network has a security risk by means of a TCP bypass attack, thereby alleviating the technical problem that traditional technologies cannot determine whether the IPID policy defect in the IPv4 / IPv6 dual-stack network has a security risk by means of a TCP bypass attack.

[0156] Optionally, the IPID acquisition unit is further used to: forge an ICMPv6 PacketTooBig message and send it to the victim host, wherein the ICMPv6 PacketTooBig message carries a forged MTU value; construct an ICMPv6 Echo Request message with a length greater than the forged MTU value and send it to the victim host; and determine the IPID based on the fragment extension header of the victim host's egress message.

[0157] Optionally, the degradation and determination unit is also used to: impersonate the IPv4 address of the router in the communication path between the victim host and the victim client, and send a forged ICMP Fragmentation Needed message to the victim host, so that the victim host uses a 2048 hash counter strategy to allocate an IPID for the IPv4 message sent to the victim client, wherein the forged ICMPFragmentation Needed message is used to indicate that the next-hop MTU value of the router between the victim host and the victim client is a preset value, and fragmentation of the export message is not allowed.

[0158] Optionally, the detection unit is also used to: send an IPv6 ICMP Echo Request message to the victim host with the attacking IPv6 address, and obtain the IPID carried in the segment extension header of the corresponding outgoing message; send a forged SYN / ACK message with a guessed source port number to the victim host by impersonating the IPv4 address of the victim client; continue to send an IPv6 ICMP Echo Request message to the victim host with the attacking IPv6 address, and obtain the IPID carried in the segment extension header of the corresponding outgoing message; determine whether the guessed source port number is the source port number of the IPv4 TCP connection between the victim host and the victim client based on the change of the IPID, wherein the change of the IPID is the difference between the two latest obtained IPIDs; if the guessed source port number is not the IPv4 The source port number of the TCP connection is obtained, a new guessed source port number is obtained, and the new guessed source port number is used as the guessed source port number, and the process returns to the step of sending a forged SYN / ACK message with the guessed source port number to the victim host by impersonating the victim client's IPv4 address, until the guessed source port number is the source port number of the IPv4 TCP connection between the victim host and the victim client, thereby obtaining the source port number of the IPv4 TCP connection between the victim host and the victim client.

[0159] Optionally, the detection unit is further used to: send an IPv6 ICMP Echo Request message to the victim host with the attacking IPv6 address, and obtain the IPID carried in the segment extension header of the corresponding egress message; send a forged RST message with a guessed sequence number to the victim host by impersonating the victim client's IPv4 address; continue to send an IPv6 ICMP Echo Request message to the victim host with the attacking IPv6 address; Request message, and obtain the IPID carried in the segment extension header of the corresponding egress message; determine whether the guessed sequence number is an acceptable sequence number in the receive window according to the change of the IPID, wherein the change of the IPID is the difference between the two most recently obtained IPIDs; if the guessed sequence number is not an acceptable sequence number in the receive window, obtain a new guessed sequence number, and use the new guessed sequence number as the guessed sequence number, and return to execute the step of sending a forged RST message with the guessed sequence number to the victim host by impersonating the victim client's IPv4 address until the guessed sequence number is an acceptable sequence number in the receive window, thereby obtaining an acceptable sequence number in the receive window; determine the challenge ACK window based on the acceptable sequence number; and detect the lower boundary of the receive window and the lower boundary of the send window according to the acceptable sequence number and the challenge ACK window.

[0160] Optionally, the detection unit is further used to: send an IPv6 ICMP Echo Request message to the victim host using the attacking IPv6 address, and obtain the IPID carried in the fragment extension header of the corresponding outbound message; send a forged ACK message with a guessed ACK to the victim host using the IPv4 address of the victim client; continue to send IPv6 ICMP Echo Request messages to the victim host using the attacking IPv6 address, and obtain the IPID carried in the fragment extension header of the corresponding outbound message; determine whether the guessed ACK is within the challenge ACK window based on the change of the IPID, wherein the change of the IPID is the difference between the two most recently obtained IPIDs; if the guessed ACK is within the challenge ACK window, determine the challenge ACK window based on the guessed ACK; if the guessed ACK is not within the challenge ACK window, obtain a new guessed ACK, and use the new guessed ACK as the guessed ACK, and return to the step of sending a forged ACK message with the guessed ACK to the victim host using the IPv4 address of the victim client, until the guessed ACK is within the challenge ACK window, and then determine the challenge ACK window based on the guessed ACK finally obtained.

[0161] Optionally, the detection unit is further used to: send an IPv6 ICMP EchoRequest message to the victim host using the attacking IPv6 address, and obtain the IPID carried in the segment extension header of the corresponding egress message; send a forged ACK message to the victim host using the IPv4 address of the victim client, in which the ACK is a preset ACK in the query ACK window and the sequence number is a current sequence number determined according to the acceptable sequence number; continue to send an IPv6 ICMP EchoRequest message to the victim host using the attacking IPv6 address; The attacking IPv6 ICMP Echo Request message is sent to the victim host, and the IPID carried in the fragment extension header of the corresponding outgoing message is obtained; the frequency jitter of the obtained IPID is used to determine whether the current sequence number is the lower boundary of the receiving window; if the current sequence number is not the lower boundary of the receiving window, a new sequence number is determined based on the acceptable sequence number, and the new sequence number is used as the current sequence number determined based on the acceptable sequence number, and the step of returning to execute the step of using the victim client's IPv4 address to send a forged ACK message to the victim host, with the ACK being the preset ACK in the query ACK window and the sequence number being the current sequence number determined based on the acceptable sequence number, until the current sequence number is the lower boundary of the receiving window, thereby obtaining the lower boundary of the receiving window; an IPv6 ICMP Echo Request message is sent to the victim host using the attacking IPv6 address, and the IPID carried in the fragment extension header of the corresponding outgoing message is obtained; an IPv6 ICMP Echo Request message is sent to the victim host using the attacking IPv6 address, and the IPID carried in the fragment extension header of the corresponding outgoing message is obtained; an IPv6 ICMP Echo Request message is sent to the victim host using the attacking IPv6 address, with the sequence number being the preset sequence number above the lower boundary of the receiving window and the ACK being the forged ACK message of the current ACK determined based on the preset ACK, and the attacking IPv6 ICMP Echo Request message, and obtain the IPID carried in the segment extension header of the corresponding outbound message; determine whether the current ACK is the lower boundary of the sending window according to the frequency jitter of the obtained IPID; if the current ACK is not the lower boundary of the sending window, determine a new ACK according to the preset ACK, and use the new ACK as the current ACK determined according to the preset ACK, and return to execute the steps of using the victim client's IPv4 address to send a forged ACK message to the victim host, the sequence number of which is a preset sequence number above the lower boundary of the receiving window and the ACK is the current ACK determined according to the preset ACK, until the current ACK is the lower boundary of the sending window, thereby obtaining the lower boundary of the sending window.

[0162] The device provided in the embodiment of the present invention has the same implementation principle and technical effects as those in the aforementioned method embodiment. For the sake of brief description, for matters not mentioned in the device embodiment, reference can be made to the corresponding content in the aforementioned method embodiment.

[0163] like Figure 12As shown, an electronic device 600 provided in an embodiment of the present application includes: a processor 601, a memory 602 and a bus, wherein the memory 602 stores machine-readable instructions executable by the processor 601. When the electronic device is running, the processor 601 communicates with the memory 602 through the bus, and the processor 601 executes the machine-readable instructions to perform the steps of the risk verification method for IPID policy defects in the IPv4 / IPv6 dual-stack network as mentioned above.

[0164] Specifically, the above-mentioned memory 602 and processor 601 can be general-purpose memories and processors, which are not specifically limited here. When the processor 601 runs the computer program stored in the memory 602, it can execute the risk verification method for the above-mentioned IPv4 / IPv6 dual-stack network IPID policy defects.

[0165] The processor 601 may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method can be completed by an integrated logic circuit of hardware in the processor 601 or by instructions in the form of software. The above-mentioned processor 601 can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components. The various methods, steps, and logic block diagrams disclosed in the embodiments of the present application can be implemented or executed. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor, etc. The steps of the method disclosed in conjunction with the embodiments of the present application can be directly embodied as being executed by a hardware decoding processor, or can be executed by a combination of hardware and software modules in the decoding processor. The software module can be located in a storage medium well-known in the art, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, etc. The storage medium is located in memory 602, and processor 601 reads the information in memory 602 and performs the steps of the above method in conjunction with its hardware.

[0166] Corresponding to the above-mentioned risk verification method for IPv4 / IPv6 dual-stack network IPID policy defects, an embodiment of the present application also provides a computer-readable storage medium, which stores machine-executable instructions. When the computer-executable instructions are called and executed by a processor, the computer-executable instructions prompt the processor to execute the steps of the above-mentioned risk verification method for IPv4 / IPv6 dual-stack network IPID policy defects.

[0167] The risk verification device for IPv4 / IPv6 dual-stack network IPID policy defects provided in the embodiment of the present application can be specific hardware on the device or software or firmware installed on the device. The implementation principle and technical effects of the device provided in the embodiment of the present application are the same as those of the aforementioned method embodiment. For the sake of brief description, for matters not mentioned in the device embodiment, reference can be made to the corresponding contents in the aforementioned method embodiment. Those skilled in the art can clearly understand that for the convenience and simplicity of description, the specific working processes of the systems, devices and units described above can all refer to the corresponding processes in the aforementioned method embodiment, and will not be repeated here.

[0168] In the embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are merely schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some communication interface, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0169] For another example, the flowcharts and block diagrams in the accompanying drawings show the possible architectures, functions and operations of the devices, methods and computer program products according to multiple embodiments of the present application. In this regard, each box in the flowchart or block diagram can represent a module, a program segment or a part of code, and the module, program segment or a part of code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in an order different from that marked in the accompanying drawings. For example, two consecutive boxes can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and the combination of the boxes in the block diagram and / or flowchart, can be implemented with a dedicated hardware-based system that performs the specified function or action, or can be implemented with a combination of dedicated hardware and computer instructions.

[0170] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0171] In addition, each functional unit in the embodiments provided in the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0172] If the functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, or the portion that contributes to the prior art, or the portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for enabling an electronic device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the risk verification method for IPv4 / IPv6 dual-stack network IPID policy defects described in various embodiments of this application. The aforementioned storage medium includes various media that can store program code, such as a USB flash drive, a mobile hard drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.

[0173] It should be noted that similar numbers and letters represent similar items in the following figures. Therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures. In addition, the terms "first", "second", "third", etc. are only used to distinguish the description and are not to be understood as indicating or implying relative importance.

[0174] Finally, it should be noted that the above-described embodiments are only specific implementation methods of the present application, which are used to illustrate the technical solutions of the present application, rather than to limit them. The scope of protection of the present application is not limited thereto. Although the present application has been described in detail with reference to the above-mentioned embodiments, those skilled in the art should understand that any person skilled in the art can modify or easily conceive of changes to the technical solutions described in the above-mentioned embodiments within the technical scope disclosed in the present application, or perform equivalent replacements for some of the technical features thereof. However, these modifications, changes, or replacements do not deviate the essence of the corresponding technical solutions from the scope of the technical solutions of the embodiments of the present application. They should all be included in the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.

Claims

1. A risk verification method for IPv4 / IPv6 dual stack network IPID policy defects, characterized in that: include: When communicating with the victim host via an IPv6 communication message, causing the segment extension header of the egress message of the victim host to carry the IPID; Downgrading the IPID policy used by the victim host to send IPv4 packets to the victim client to a 2048-hash counter policy, and then communicating with the victim host by changing the IPv6 address until an attacking IPv6 address that shares the same hash IPID counter as the victim client IPv4 address is determined; When communicating with the victim host based on the attacking IPv6 address, detecting the source port number, the lower boundary of the receive window, and the lower boundary of the send window of the IPv4 TCP connection between the victim host and the victim client according to the IPID carried in the segment extension header of the egress message; The source port number, the lower boundary of the receive window, and the lower boundary of the send window are used as sensitive information of the IPv4 / IPv6 dual-stack network, and it is determined that the IPID policy defect of the IPv4 / IPv6 dual-stack network has the risk of TCP bypass attack; When determining the attacking IPv6 address that shares the same hashed IPID counter as the victim client's IPv4 address, the attacker monitors the IPID value in the response data packet returned from the victim host; if the data packets of the attacker's IPv6 address and the victim client's IPv4 address are assigned consecutive or similar IPID values, then it is determined that the attacker's IPv6 address and the victim client's IPv4 address share the same hashed IPID counter, and the IPv6 address at this time is the attacking IPv6 address; Wherein, when communicating with the victim host based on the attacking IPv6 address, the source port number of the IPv4 TCP connection between the victim host and the victim client and the lower boundary of the receiving window and the lower boundary of the sending window are detected according to the IPID carried in the segmentation extension header of the egress message, including: sending an IPv6 ICMP Echo Request message to the victim host with the attacking IPv6 address, and obtaining the IPID carried in the segmentation extension header of the corresponding egress message; sending a forged SYN / ACK message with a guessed source port number and a forged RST message with a guessed sequence number to the victim host by impersonating the IPv4 address of the victim client; continuing to send an IPv6 ICMP Echo Request message to the victim host with the attacking IPv6 address, and obtaining the IPID carried in the segmentation extension header of the corresponding egress message; determining whether the guessed source port number is the IPv4 TCP connection between the victim host and the victim client according to the change of the IPID. The source port number of the TCP connection and the guessed sequence number are whether they are acceptable sequence numbers in the receiving window, wherein the change of the IPID is the difference between the two most recently obtained IPIDs; if the guessed source port number is not the source port number of the IPv4 TCP connection between the victim host and the victim client, and the guessed sequence number is not an acceptable sequence number in the receiving window, then a new guessed source port number and a new guessed sequence number are obtained, and the new guessed source port number is used as the guessed source port number and the new guessed sequence number is used as the guessed sequence number, and the step of sending a forged SYN / ACK message with a guessed source port number and a forged RST message with a guessed sequence number to the victim host by impersonating the IPv4 address of the victim client is returned until the guessed source port number is the source port number of the IPv4 TCP connection between the victim host and the victim client, and the guessed sequence number is an acceptable sequence number in the receiving window, thereby obtaining the IPv4 address of the victim host and the victim client. The method comprises the following steps: determining a source port number of a TCP connection and an acceptable sequence number in the receiving window; determining a challenge ACK window based on the acceptable sequence number; and detecting a lower boundary of the receiving window and a lower boundary of the sending window according to the acceptable sequence number and the challenge ACK window.

2. The method according to claim 1, characterized in that When communicating with a victim host via an IPv6 communication message, the segment extension header of the victim host's egress message carries an IPID, including: Forging an ICMPv6 PacketTooBig message and sending it to the victim host, wherein the ICMPv6 PacketTooBig message carries a forged MTU value; Constructing an ICMPv6 Echo Request message whose length is greater than the forged MTU value and sending it to the victim host; The IPID is determined according to a segment extension header of an egress message of the victim host.

3. The method according to claim 1, characterized in that The IPID policy for the victim host to send IPv4 packets to the victim client is downgraded to a 2048-hash counter policy, including: By impersonating the IPv4 address of the router in the communication path between the victim host and the victim client, a forged ICMP Fragmentation Needed message is sent to the victim host, so that the victim host uses a 2048 hash counter strategy to allocate an IPID for the IPv4 message sent to the victim client, wherein the forged ICMP Fragmentation Needed message is used to indicate that the next-hop MTU value of the router between the victim host and the victim client is a preset value, and segmentation of the egress message is not allowed.

4. The method according to claim 1, wherein Determining a challenge ACK window based on the acceptable sequence number includes: Send an IPv6 ICMP Echo Request message to the victim host using the attacking IPv6 address, and obtain the IPID carried in the fragment extension header of the corresponding egress message; Sending a forged ACK message with a guessed ACK to the victim host by impersonating the victim client's IPv4 address; Continue to send IPv6 ICMP Echo Request messages to the victim host using the attacking IPv6 address, and obtain the IPID carried in the fragment extension header of the corresponding egress message; Determining whether the guessed ACK is within the challenge ACK window according to a change in the IPID, wherein the change in the IPID is a difference between two newly obtained IPIDs; If the guessed ACK is within the challenge ACK window, determining the challenge ACK window according to the guessed ACK; If the guessed ACK is not within the challenge ACK window, a new guessed ACK is obtained and used as the guessed ACK. The process returns to the step of sending a forged ACK message with the guessed ACK to the victim host by impersonating the victim client's IPv4 address until the guessed ACK is within the challenge ACK window, and the challenge ACK window is then determined based on the guessed ACK finally obtained.

5. The method according to claim 1, characterized in that Detecting the lower boundary of the receiving window and the lower boundary of the sending window according to the acceptable sequence number and the challenge ACK window includes: Send an IPv6 ICMP Echo Request message to the victim host using the attacking IPv6 address, and obtain the IPID carried in the fragment extension header of the corresponding egress message; Sending a forged ACK message to the victim host by impersonating the victim client IPv4 address, wherein the ACK is a preset ACK in the challenge ACK window and the sequence number is a current sequence number determined according to the acceptable sequence number; Continue to send IPv6 ICMP Echo Request messages to the victim host using the attacking IPv6 address, and obtain the IPID carried in the fragment extension header of the corresponding egress message; Determining whether the current sequence number is the lower boundary of the receiving window according to the frequency jitter of the obtained IPID; If the current sequence number is not the lower boundary of the receive window, determining a new sequence number based on the acceptable sequence number, and using the new sequence number as the current sequence number determined based on the acceptable sequence number, returning to the step of using the victim client's IPv4 address to send a forged ACK message to the victim host, where the ACK is a preset ACK in the challenge ACK window and the sequence number is the current sequence number determined based on the acceptable sequence number, until the current sequence number is the lower boundary of the receive window, thereby obtaining the lower boundary of the receive window; Send an IPv6 ICMP Echo Request message to the victim host using the attacking IPv6 address, and obtain the IPID carried in the fragment extension header of the corresponding egress message; Using the IPv4 address of the victim client to send a forged ACK message to the victim host, wherein the sequence number is a preset sequence number above the lower boundary of the receiving window and the ACK is a current ACK determined according to the preset ACK; Continue to send IPv6 ICMP Echo Request messages to the victim host using the attacking IPv6 address, and obtain the IPID carried in the fragment extension header of the corresponding egress message; Determining whether the current ACK is the lower boundary of the sending window according to the frequency jitter of the obtained IPID; If the current ACK is not the lower boundary of the sending window, a new ACK is determined based on the preset ACK, and the new ACK is used as the current ACK determined based on the preset ACK. The process returns to the step of using the victim client's IPv4 address to send a forged ACK message to the victim host, with a sequence number that is a preset sequence number above the lower boundary of the receiving window and an ACK that is the current ACK determined based on the preset ACK, until the current ACK is the lower boundary of the sending window, thereby obtaining the lower boundary of the sending window.

6. A risk verification device for IPv4 / IPv6 dual stack network IPID policy defects, characterized in that: include: An IPID acquiring unit, configured to, when communicating with a victim host via an IPv6 communication message, cause the segment extension header of an egress message of the victim host to carry the IPID; a downgrading and determining unit, configured to downgrade the IPID policy for the victim host to send IPv4 packets to the victim client to a policy based on 2048 hash counters, and then communicate with the victim host by changing the IPv6 address until an attacking IPv6 address that shares the same hash IPID counter with the victim client IPv4 address is determined; a detection unit, configured to detect, when communicating with the victim host based on the attacking IPv6 address, the source port number, the lower boundary of the receive window, and the lower boundary of the send window of the IPv4 TCP connection between the victim host and the victim client according to the IPID carried in the segment extension header of the egress message; a setting and determining unit, configured to use the source port number, the lower boundary of the receive window, and the lower boundary of the send window as sensitive information of the IPv4 / IPv6 dual stack network, and determine that an IPID policy defect of the IPv4 / IPv6 dual stack network presents a risk of a TCP bypass attack; The degradation and determination unit is further configured to: when determining an attacking IPv6 address that shares a hashed IPID counter with the victim client IPv4 address, the attacker monitors an IPID value in a response data packet returned from the victim host; if data packets of the attacker's IPv6 address and the victim client's IPv4 address are assigned consecutive or similar IPID values, then it is determined that the attacker's IPv6 address and the victim client's IPv4 address share the same hashed IPID counter, and the IPv6 address at this time is the attacking IPv6 address; Wherein, the detection unit is further used to: send an IPv6 ICMP Echo Request message to the victim host with the attacking IPv6 address, and obtain the IPID carried in the segment extension header of the corresponding outgoing message; use the IPv4 address of the victim client to send a forged SYN / ACK message with a guessed source port number and a forged RST message with a guessed sequence number to the victim host; continue to send an IPv6 ICMP Echo Request message to the victim host with the attacking IPv6 address, and obtain the IPID carried in the segment extension header of the corresponding outgoing message; determine whether the guessed source port number is the IPv4 address of the victim host and the victim client according to the change of the IPID The source port number of the TCP connection and the guessed sequence number are whether they are acceptable sequence numbers in the receiving window, wherein the change of the IPID is the difference between the two most recently obtained IPIDs; if the guessed source port number is not the source port number of the IPv4 TCP connection between the victim host and the victim client, and the guessed sequence number is not an acceptable sequence number in the receiving window, then a new guessed source port number and a new guessed sequence number are obtained, and the new guessed source port number is used as the guessed source port number and the new guessed sequence number is used as the guessed sequence number, and the step of sending a forged SYN / ACK message with a guessed source port number and a forged RST message with a guessed sequence number to the victim host by impersonating the IPv4 address of the victim client is returned until the guessed source port number is the source port number of the IPv4 TCP connection between the victim host and the victim client, and the guessed sequence number is an acceptable sequence number in the receiving window, thereby obtaining the IPv4 address of the victim host and the victim client. The method comprises the following steps: determining a source port number of a TCP connection and an acceptable sequence number in the receiving window; determining a challenge ACK window based on the acceptable sequence number; and detecting a lower boundary of the receiving window and a lower boundary of the sending window according to the acceptable sequence number and the challenge ACK window.

7. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 5 are implemented.

8. A computer-readable storage medium, characterized in that The computer-readable storage medium stores machine-executable instructions. When the machine-executable instructions are called and executed by a processor, the machine-executable instructions prompt the processor to execute the method according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Bypass ICMP redirection attack defense method and device based on switch active verification

    CN118573429A

  • Non-disruptive ddos testing

    US20180046811A1