Source address verification deployment detection method based on IPv6 tunnel routing node
By decapsulating and forwarding detection packets by IPv6 tunnel routing nodes, the problem of limited measurement coverage of source address spoofing attacks in the prior art is solved, and extensive evaluation and reliable measurement of the deployment of source address verification of IPv4 and IPv6 networks is achieved.
Patent Information
- Application Number
- CN202510655849.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-21
- Publication Date
- 2025-08-12
AI Technical Summary
In the prior art, the coverage of the measurement methods of source address spoofing attacks is limited, making it difficult to effectively evaluate the deployment of source address verification under IPv4 and IPv6 networks.
Using the IPv6 tunnel routing node as a remote measurement point, the ISAV and OSAV deployment status of the target network is determined by sending and receiving double-layer encapsulated detection messages, including sending detection messages from the controlled host to the measured network, and decapsulating and forwarding some inner-layer messages through the IPv6 tunnel routing node, and judging the deployment status based on the message reception situation.
It enables extensive evaluation of ISAV under IPv4 and OSAV deployment under IPv6 without deploying measurement points within the network under test, improves measurement coverage and reliability, and provides a more comprehensive network security assessment.
Smart Images

Figure CN120474786A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network security technology, specifically to the field of network security technology in an IPv6 network environment, and more particularly to a source address verification deployment detection method based on IPv6 tunnel routing nodes. Background Art
[0002] In related technologies, source address spoofing attacks are one of the most common attacks on the Internet. To mitigate source address spoofing attacks, SAV (Source Address Validation) technology has emerged. Correspondingly, measuring the deployment of SAV is also crucial.
[0003] Currently, methods for measuring SAV deployment typically include: 1. Crowdsourcing, which relies on the cooperation of volunteers and limits the measurement scope; 2. Traffic analysis, which requires the cooperation of specific network administrators, limiting coverage and reproducibility; 3. Misconfiguration, which requires the target network to be misconfigured, limiting coverage; and 4. Protocol side-channel, which determines SAV deployment by observing the reaction of forged source address packets entering the target network, but can only measure ISAV (Ingress Source Address Validation). Clearly, the SAV deployment measurement methods in related technologies suffer from at least limited coverage. Summary of the Invention
[0004] The present application aims to solve one of the technical problems in the related art at least to a certain extent.
[0005] To this end, the first purpose of this application is to propose a source address verification deployment detection method based on IPv6 tunnel routing nodes to realize the detection of ISAV under IPv4 and OSAV under IPv6 deployment status, with a wider coverage range; at the same time, it can also realize the collection of IPv4-IPv6 address pairs, so that the inner part of the detection message can be forwarded and smoothly reach the destination address, thereby expanding the effective range of the measurement.
[0006] The second purpose of this application is to propose a source address verification deployment detection device based on IPv6 tunnel routing nodes.
[0007] The third objective of this application is to provide an electronic device.
[0008] The fourth object of this application is to provide a computer-readable storage medium.
[0009] A fifth object of this application is to provide a computer program product.
[0010] To achieve the above objectives, the first embodiment of the present application proposes a source address verification deployment detection method based on IPv6 tunnel routing nodes, including:
[0011] Send a first probe message from the controlled host to all IPv4 addresses in the tested network; wherein the outer IPv4 source address of the first probe message is the real IPv4 address of the controlled host, the inner IPv6 source address is a pure IPv6 address, and the inner IPv6 destination address is the IPv6 address of the controlled host;
[0012] After receiving the first detection message, the IPv6 tunnel routing node in the tested network decapsulates the inner portion of the first detection message and forwards the message to the controlled host;
[0013] Determine, by the controlled host, a target IPv6 tunnel routing node in the network under test based on the inner portion of the message;
[0014] Sending a second detection message to the target IPv6 tunnel routing node through the controlled host; wherein the outer IPv4 source address of the second detection message is an address inside the measured network;
[0015] After the target IPv6 tunnel routing node receives the second detection message, forwarding the inner part of the second detection message to the controlled host;
[0016] The controlled host determines the target network's entry source address under IPv4 to verify the ISAV deployment status based on the message reception status forwarded by the target IPv6 tunnel routing node.
[0017] To achieve the above-mentioned purpose, the second embodiment of the present application proposes a source address verification deployment detection device based on an IPv6 tunnel routing node, comprising:
[0018] A first message sending module is used to send a first detection message from the controlled host to all IPv4 addresses in the measured network; wherein the outer IPv4 source address of the first detection message is the real IPv4 address of the controlled host, the inner IPv6 source address is a pure IPv6 address, and the inner IPv6 destination address is the IPv6 address of the controlled host;
[0019] A first forwarding module is configured to decapsulate an inner portion of the first detection message and forward the inner portion of the first detection message to the controlled host after the IPv6 tunnel routing node in the measured network receives the first detection message;
[0020] A determination module, configured to determine, through the controlled host, a target IPv6 tunnel routing node in the tested network based on the inner portion of the message;
[0021] A second message sending module is used to send a second detection message to the target IPv6 tunnel routing node through the controlled host; wherein the outer IPv4 source address of the second detection message is an address inside the measured network;
[0022] A second forwarding module is configured to forward an inner portion of the second detection message to the controlled host after the target IPv6 tunnel routing node receives the second detection message;
[0023] The deployment detection module is used to determine the target network's IPv4 source address verification ISAV deployment status through the controlled host according to the message reception status forwarded by the target IPv6 tunnel routing node.
[0024] To achieve the above-mentioned purpose, a third embodiment of the present application provides an electronic device, comprising: a processor, and a memory communicatively connected to the processor;
[0025] The memory stores computer-executable instructions;
[0026] The processor executes the computer-executable instructions stored in the memory to implement any method described in the first aspect above.
[0027] To achieve the above-mentioned purpose, the fourth embodiment of the present application proposes a computer-readable storage medium, which stores computer-executable instructions. When the computer-executable instructions are executed by a processor, they are used to implement any one of the methods described in the first aspect above.
[0028] To achieve the above-mentioned purpose, the fifth embodiment of the present application proposes a computer program product, including a computer program, which implements any method described in the first aspect when executed by a processor.
[0029] The present application provides a source address verification deployment detection method based on IPv6 tunnel routing node, which sends a first detection message from a controlled host to all IPv4 addresses in the tested network; wherein, the outer IPv4 source address of the first detection message is the real IPv4 address of the controlled host, the inner IPv6 source address is a pure IPv6 address, and the inner IPv6 destination address is the IPv6 address of the controlled host; after the IPv6 tunnel routing node in the tested network receives the first detection message, the inner part of the message in the first detection message is decapsulated and forwarded to the controlled host; the controlled host verifies the authenticity of the message based on the IPv4 address of the controlled host, and sends the verification message to the controlled host. The inner portion of the message determines the target IPv6 tunnel routing node in the network under test; a second probe message is sent to the target IPv6 tunnel routing node via the controlled host; the outer IPv4 source address of the second probe message is forged to be an address within the network under test; after the target IPv6 tunnel routing node receives the second probe message, it forwards the inner portion of the second probe message to the controlled host; and the controlled host determines the target network's IPv4 source address based on the reception of the message forwarded by the target IPv6 tunnel routing node, thereby verifying the ISAV deployment status. This allows measurement of the ISAV deployment status under IPv4 without deploying measurement points within the network under test, thus providing a wider coverage area.
[0030] Additional aspects and advantages of the present application will be given in part in the description below, and in part will become apparent from the description below, or will be learned through practice of the present application. BRIEF DESCRIPTION OF THE DRAWINGS
[0031] The above and / or additional aspects and advantages of the present application will become apparent and easily understood from the following description of the embodiments in conjunction with the accompanying drawings, in which:
[0032] Figure 1 A flow chart of a method for source address verification and deployment detection based on IPv6 tunnel routing nodes provided in an embodiment of the present application;
[0033] Figure 2 A flow chart of a method for source address verification and deployment detection based on IPv6 tunnel routing nodes provided in an embodiment of the present application;
[0034] Figure 3 This is a schematic diagram illustrating an example of an ISAV deployment measurement method under IPv4 provided in an embodiment of the present application;
[0035] Figure 4 This is a schematic diagram illustrating an example of an OSAV deployment measurement method under IPv6 provided in an embodiment of the present application;
[0036] Figure 5This is a schematic diagram illustrating an example of a method for collecting IPv4-IPv6 address pairs provided in an embodiment of the present application;
[0037] Figure 6 A schematic diagram of the structure of a source address verification deployment detection device based on IPv6 tunnel routing nodes provided in an embodiment of the present application. DETAILED DESCRIPTION
[0038] The following describes in detail embodiments of the present application, examples of which are shown in the accompanying drawings, wherein the same or similar reference numerals throughout represent the same or similar elements or elements having the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are intended to be used to explain the present application, and should not be construed as limiting the present application.
[0039] Among related technologies, source address spoofing attacks are one of the most common attacks on the Internet. Attackers carry out malicious actions by forging the source address of data packets. This attack forms the basis of a series of other attacks, such as denial of service (DoS), security policy bypass, and cache poisoning. To mitigate source address spoofing attacks, SAV technology was proposed. SAV technology is deployed at the edge of the network to verify the legitimacy of the source address of data packets and filter out malicious traffic. Based on the direction of the inspected traffic, SAV can be divided into two categories: ISAV and OSAV. ISAV is used to prevent traffic entering the network from forging internal source addresses of the network; OSAV is used to prevent traffic leaving the network from using source addresses that do not belong to the network. Although SAV can effectively prevent address spoofing attacks, the actual deployment of SAV on the Internet is still very limited due to various reasons such as knowledge, technology, cost, and management. Measuring the deployment of SAV is crucial for identifying networks vulnerable to spoofed data packets and revealing network security issues.
[0040] Related work on measuring SAV deployment can be categorized into the following categories:
[0041] 1) Project Spoofer: This approach recruits volunteers to run clients within the network being tested, sending or receiving packets with forged source addresses on their hosts to assess the deployment of SAVs. However, this approach relies on the cooperation of volunteers and can only measure a very small number of networks. This approach relies on the cooperation of volunteers, resulting in a very limited measurement scope. 2) Traffic analysis-based approaches: For example, these approaches capture and analyze traffic data from Internet Exchange Points (IXPs) to determine the deployment of SAVs on a network. This approach requires the cooperation of specific network administrators and has limited coverage and reproducibility. 3) Misconfiguration-based approaches: These approaches leverage network misconfigurations, such as DNS (Domain Name System) forwarding and routing loops, to measure SAV deployment by sending packets with forged source addresses. This approach requires the target network to be misconfigured and has limited coverage. 4) Protocol side channel-based approaches: These approaches, such as DNS reflection, IPID (Identification Field) growth, and IP fragmentation, assess SAV deployment by observing the response of packets with forged source addresses entering the target network. This approach can only measure ISAVs.
[0042] As can be seen, the SAV deployment measurement schemes used in related technologies have certain limitations. First, their coverage is limited, and the measured results are relatively unrepresentative. For example, the Spoofer project conducted continuous measurements for a decade, but its results only covered approximately 2,000 autonomous systems. Second, work based on protocol side channels can only measure the deployment of ISAVs, not OSAVs.
[0043] Based on this, the present application proposes a source address verification deployment detection method based on IPv6 tunnel routing nodes, which can utilize the IPv6 tunnel routing nodes existing in the network. According to the tunnel protocol specification, these IPv6 tunnel routing nodes can receive double-layer encapsulated messages with an inner layer of IPv6 and an outer layer of IPv4, and decapsulate the inner layer message before forwarding it. Based on this feature, the IPv6 tunnel routing nodes in the network can be used as remote measurement points to remotely send data packets and remotely confirm data packet reception. By utilizing this remote measurement point, it is possible to verify whether data packets using forged source addresses enter or leave the network, thereby measuring the network's ISAV deployment status under IPv4 and OSAV deployment status under IPv6.
[0044] The following describes a method and apparatus for source address verification deployment detection based on IPv6 tunnel routing nodes according to an embodiment of the present application with reference to the accompanying drawings.
[0045] Figure 1 A flow chart of a source address verification deployment detection method based on IPv6 tunnel routing nodes provided in an embodiment of the present application is shown as follows: Figure 1 As shown, the source address verification deployment detection method based on IPv6 tunnel routing node includes the following steps:
[0046] Step 101: Send a first detection message from the controlled host to all IPv4 addresses in the tested network.
[0047] The outer IPv4 source address of the first detection message is the real IPv4 address of the controlled host, the inner IPv6 source address is a pure IPv6 address, and the inner IPv6 destination address is the IPv6 address of the controlled host.
[0048] In an embodiment of the present application, the deployment of ISAV source address verification under IPv4 on a target network (i.e., the network under test) can be measured using only a dual-stack controlled host located outside the network under test. For example, a probe message (i.e., a first probe message) can be first sent from the controlled host to all IPv4 (Internet Protocol version 4) addresses within the network under test to discover IPv6 (Internet Protocol version 6) tunnel routing nodes that can serve as remote measurement points. As an example, the first probe message is an ICMPv6 Echo Request message encapsulated in an IPv4 message. The ICMPv6 Echo Request message is a message type in the Internet Control Message Protocol version 6 (ICMPv6) and can be used to test the connectivity between two nodes in the network; the outer IPv4 source address of the first probe message is the real IPv4 address of the controlled host to ensure that the first probe message can reach the destination normally; the inner IPv6 source address of the first probe message uses a pure IPv6 address, and the inner IPv6 destination address uses the IPv6 address of the controlled host.
[0049] Step 102: After receiving the first detection message, the IPv6 tunnel routing node in the network under test decapsulates the inner portion of the first detection message and forwards it to the controlled host.
[0050] In an embodiment of the present application, when the IPv6 tunnel routing node in the network under test receives the detection message, it can decapsulate the message (i.e., the first detection message) and forward the inner part of the first detection message (inner part message), and the inner part message of the first detection message forwarded by the IPv6 tunnel routing node will reach the controlled host.
[0051] Furthermore, the IPv4 address information of the destination address can be embedded in the ICMPv6 data segment of the first detection message. In this way, when the IPv6 tunnel routing node forwards the inner portion of the first detection message, the IPv4 address of the destination can be embedded in the ICMPv6 data segment of the inner portion of the first detection message, so that the controlled host can confirm which node (IPv6 tunnel routing node) forwarded the received message.
[0052] Step 103: Determine the target IPv6 tunnel routing node in the tested network based on the inner portion of the message by the controlled host.
[0053] In an embodiment of the present application, after the IPv6 tunnel routing node in the tested network decapsulates the inner part of the first detection message and forwards it to the controlled host, the forwarded message (that is, the inner part of the decapsulated first detection message forwarded by the IPv6 tunnel routing node) can be monitored on the controlled host, and the available IPv6 tunnel routing node, that is, the target IPv6 tunnel routing node, can be determined in the target network.
[0054] Furthermore, when the controlled host determines the target IPv6 tunnel routing node in the network under test based on the inner portion of the message, the target IPv6 tunnel routing node in the network under test can be determined based on the inner portion of the message and the embedded IPv4 address information. For example, the controlled host can extract the source address of the inner IPv6 message, which is the IPv6 address of the sender of the response message (i.e., the IPv6 tunnel routing node); the controlled host can also extract the embedded IPv4 address information from the ICMPv6 data segment to confirm which IPv4 address node forwarded the response message. Then, the received IPv6 address is matched with the embedded IPv4 address, and the IPv4-IPv6 address pair of the IPv6 tunnel routing node is recorded. That is, the controlled host can receive and parse the message forwarded by the IPv6 tunnel routing node, thereby determining the IPv4 and IPv6 address pair of the target IPv6 tunnel routing node in the network under test.
[0055] Step 104: Send a second detection message to the target IPv6 tunnel routing node through the controlled host.
[0056] The outer IPv4 source address of the second detection message is an address inside the network under test.
[0057] In an embodiment of the present application, after determining the target IPv6 tunnel routing node, a new probe message, i.e., a second probe message, can be sent from the controlled host to the discovered available IPv6 tunnel routing node. The second probe message is similar to the message originally sent (such as the first probe message), but the outer IPv4 source address is forged to be an address inside the network being tested. For example, if the IPv4 address of a target IPv6 tunnel routing node is abcd, the outer source address of the second probe message can be set to abce, where e = (d + 1) mod 255.
[0058] Step 105: After receiving the second detection message, the target IPv6 tunnel routing node forwards the inner portion of the second detection message to the controlled host.
[0059] In an embodiment of the present application, if the target IPv6 tunnel routing node receives the second detection message sent by the controlled host, the inner portion of the message in the second detection message can be decapsulated and forwarded to the controlled host. As an example, after the target IPv6 tunnel routing node receives the detection message (the second detection message), it will decapsulate the outer IPv4 message of the second detection message and extract the inner IPv6 message. The inner IPv6 message is then forwarded to the controlled host. Since the destination address of the inner IPv6 message is the IPv6 address of the controlled host, the message will eventually reach the controlled host.
[0060] Step 106: The controlled host determines the target network's IPv4 source address based on the reception of the message forwarded by the target IPv6 tunnel routing node to verify the ISAV deployment status.
[0061] In an embodiment of the present application, after the target IPv6 tunnel routing node forwards the inner portion of the second probe message to the controlled host, it can determine whether the message with the forged source address has successfully entered the network under test by observing whether the forwarded message can still be received on the controlled host, thereby evaluating the ISAV deployment status of the network under test under IPv4. For example, the controlled host can check the received inner IPv6 message to confirm whether it comes from the forged source address. And based on the reception of the message, the ISAV deployment status of the network under test can be determined. For example, if the controlled host receives a message from the forged source address, then ISAV may not be deployed or there is a bypass; if the controlled host does not receive a message from the forged source address, then ISAV has been deployed.
[0062] The present application provides a source address verification deployment detection method based on IPv6 tunnel routing node, which sends a first detection message from a controlled host to all IPv4 addresses in the tested network; wherein, the outer IPv4 source address of the first detection message is the real IPv4 address of the controlled host, the inner IPv6 source address is a pure IPv6 address, and the inner IPv6 destination address is the IPv6 address of the controlled host; after the IPv6 tunnel routing node in the tested network receives the first detection message, the inner part of the message in the first detection message is decapsulated and forwarded to the controlled host; the controlled host verifies the authenticity of the message based on the IPv4 address of the controlled host, and sends the verification message to the controlled host. The inner portion of the message determines the target IPv6 tunnel routing node in the network under test; a second probe message is sent to the target IPv6 tunnel routing node via the controlled host; the outer IPv4 source address of the second probe message is forged to be an address within the network under test; after the target IPv6 tunnel routing node receives the second probe message, it forwards the inner portion of the second probe message to the controlled host; and the controlled host determines the target network's IPv4 source address based on the reception of the message forwarded by the target IPv6 tunnel routing node, thereby verifying the ISAV deployment status. This allows measurement of the ISAV deployment status under IPv4 without deploying measurement points within the network under test, thus providing a wider coverage area.
[0063] Furthermore, it is also possible to detect the OSAV deployment of the tested network under IPv6, refer to Figure 2 A flow chart of another source address verification and deployment detection method based on an IPv6 tunnel routing node is shown, which specifically includes:
[0064] Step 201: Send a third detection message from the controlled node to all IPv4 addresses in the measured network.
[0065] The third detection message is a detection message with a double-layer header structure, the outer IPv4 source address of the third detection message is the real address of the controlled host, and the inner IPv6 destination address is the IPv6 address of the controlled host;
[0066] Step 202: After receiving the third detection message, the IPv6 tunnel routing node in the network under test decapsulates the inner portion of the third detection message.
[0067] Step 203: Modify the IPv6 source address of the inner portion of the third detection message to the real IPv6 address and the forged IPv6 address of the IPv6 tunnel routing node, respectively, and forward the inner portion of the third detection message after the modified address to the controlled host;
[0068] Step 204: The controlled host determines the outbound source address of the tested network under IPv6 based on the reception of the inner portion of the third detection message after the address is modified, thereby verifying the OSAV deployment status.
[0069] In an embodiment of the present application, the measurement of OSAV deployment under IPv6 utilizes a method of sending messages on an IPv6 tunnel routing node as a remote measurement point. Exemplarily, a probe message (i.e., a third probe message) with a double-layer header structure can be sent from a controlled node to all IPv4 addresses in the measured network to discover available IPv6 tunnel routing nodes. The outer IPv4 source address of the third probe message is the real address of the controlled host to ensure that the message successfully reaches the destination. The inner IPv6 destination address is the IPv6 address of the controlled host. After the IPv6 tunnel routing node in the measured network receives the third probe message, the third probe message can be decapsulated and the inner portion of the third probe message can be forwarded. The IPv6 source address of the inner portion of the third probe message is then modified to the real IPv6 address and the forged IPv6 address of the IPv6 tunnel routing node respectively, and the inner portion of the third probe message after the modified address is forwarded to the controlled host so that the IPv6 tunnel routing node can send normal traffic and forged traffic respectively.
[0070] The controlled host can then monitor the reception of the inner portion of the third probe message after the address modification. Specifically, the controlled host checks whether the legitimate and forged traffic can leave the network under test and be received. Based on the reception of the inner portion of the third probe message, the deployment of Outbound Source Address Validation (OSAV) in the network under test under IPv6 can be determined. For example, the deployment of OSAV in the network under test can be determined based on whether or not messages with forged source addresses are received. If messages with forged source addresses are received, OSAV may not be deployed or may be bypassed; if no messages with forged source addresses are received, OSAV may be deployed. This allows OSAV deployment measurement in IPv6 without deploying any measurement points within the network under test, providing a wider coverage. Combined with the aforementioned ISAV deployment measurement in IPv4, the deployment of SAV can be effectively assessed without deploying any measurement points within the network under test, enabling comprehensive measurement of various SAV types while maintaining a high measurement coverage. Furthermore, by combining the sending and confirmation of received messages at remote measurement points with the SAV deployment measurement task, a remote measurement scheme for ISAV deployment under IPv4 and OSAV deployment under IPv6 was developed. By properly configuring the inner and outer addresses of the two-layer probe message structure, the measurement coverage and reliability were effectively improved. Furthermore, rigorous control experiments were designed to reduce experimental errors and ensure the credibility of the results.
[0071] Furthermore, the collection of IPv4-IPv6 address pairs of target IPv6 tunnel routing nodes can be achieved, specifically including:
[0072] A fourth probe message is sent from the controlled host to the IPv6 tunnel routing node; wherein the fourth probe message is an ICMPv6 Echo Request message encapsulated in an IPv4 message, the outer IPv4 source address is the real IPv4 address of the controlled host, the inner IPv6 source address is the real IPv6 address of the controlled host, the inner IPv6 destination address is a pure IPv6 address that does not belong to the network where the controlled host is located and does not belong to the network where the IPv6 tunnel routing node is located, and the Hop Limit field of the inner header is set to a preset value;
[0073] When the fourth probe message arrives at the IPv6 tunnel routing node and is decapsulated, the Hop Limit field is modified to a preset value of -1, and an error message is sent to the controlled host through the IPv6 tunnel routing node; wherein the source address of the error message is the IPv6 address of the IPv6 tunnel routing node;
[0074] In the event that the controlled host receives an error message, the IPv4-IPv6 address pair of the IPv6 tunnel routing node is recorded.
[0075] In an embodiment of the present application, the IPv4-IPv6 address pairs of the IPv6 tunnel routing nodes can also be collected to expand the coverage of the SAV measurement method. First, a probe message (i.e., the fourth probe message) can be sent from the controlled host to the tunnel routing node. The probe message is an ICMPv6 Echo Request message encapsulated in an IPv4 message. The ICMPv6 Echo Request message is a message type used in the ICMPv6 protocol to test network connectivity, and is mainly used to detect network connectivity between two IPv6 nodes. The outer IPv4 source address of the fourth probe message can be the real IPv4 address of the controlled host, the inner IPv6 source address can be the real IPv6 address of the controlled host, and the destination address can be a pure IPv6 address that does not belong to the network where the controlled host is located and does not belong to the network where the IPv6 tunnel routing node is located, and the Hop Limit field of the inner header is set to a preset value, for example, 1. The Hop Limit field is a field in the IPv6 message header used to limit the number of transmission hops of a data packet in the network. When this type of probe message is transmitted in the IPv4 Internet, the Hop Limit field will not be changed because the inner header is regarded as part of the payload. When the fourth probe message arrives at the IPv6 tunnel routing node and is decapsulated, the Hop Limit will be reduced to a preset value of -1, for example, 0. At this time, the IPv6 tunnel routing node can send an error message to the controlled host, and the source address of the error message can be the IPv6 address of the IPv6 tunnel routing node. Then, the error message sent by the IPv6 tunnel routing node can be received at the controlled host, and the IPv4-IPv6 address pair of the IPv6 tunnel routing node can be recorded. In this way, the IPv4-IPv6 address pairs can be collected on the IPv6 tunnel routing node, so that the inner part of the probe message can be forwarded and smoothly reach the destination, thereby extending the effective range of the measurement.
[0076] Furthermore, the error message type is ICMPv6 Time Exceeded. The ICMPv6 Time Exceeded error message is an error type in the ICMPv6 protocol, which is used to indicate that an IPv6 data packet is discarded during transmission because the HopLimit field value is exhausted.
[0077] To make the source address verification deployment detection method based on IPv6 tunnel routing nodes provided by the embodiment of the present disclosure clearer, the following is explained with reference to examples:
[0078] This application proposes a SAV deployment detection method based on IPv6 tunnel routing nodes. This method leverages the ubiquitous presence of IPv6 tunnel routing nodes in the network and utilizes their characteristics to serve as remote measurement points. This method can measure the ISAV deployment of the target network under IPv4 and the OSAV deployment under IPv6. This method primarily includes the following three components: 1) ISAV deployment measurement under IPv4; 2) OSAV deployment measurement under IPv6; and 3) IPv4-IPv6 address pair collection. Each of these components will be described in detail below. Specifically:
[0079] First: ISAV deployment measurement under IPv4.
[0080] The ISAV deployment status of the target network under IPv4 can be measured with only a dual-stack controlled host located outside the network being tested. The process is as follows: Figure 3 As shown, Figure 3 Prober: probe (the host that initiates the probe request); Target: target; IPv4_prober: the IPv4 address of the probe; IPv4_target: the IPv4 address of the target; IPv6_other: the IPv6 address of another node; IPv6_prober: the IPv6 address of the probe; ICMPv6 Echo Request: an ICMPv6 protocol message used to test network connectivity, similar to the ping request in IPv4; IPv4_spoof: forging an IPv4 source address; Packet (4) received? (Has packet 4 been received?): inquires whether the fourth probe packet has been received; ->no inbound SAV (->no inbound source address verification): if the fourth probe packet is received, it is inferred that ISAV is not deployed on the target network.
[0081] Reference Figure 3First, a probe message is sent from the controlled host to all IPv4 addresses within the network under test to discover IPv6 tunnel routing nodes that can be used as remote measurement points. The probe message is an ICMPv6 Echo Request message encapsulated within an IPv4 message. The outer IPv4 source address of the message is the real IPv4 address of the controlled host, ensuring that it can reach its destination. The inner IPv6 source address uses a pure IPv6 address, and the inner IPv6 destination address uses the IPv6 address of the controlled host. When an IPv6 tunnel routing node in the network receives the probe message, it decapsulates the message and forwards the inner portion. The forwarded message eventually reaches the controlled host. To confirm which node forwarded the message, the destination IPv4 address is embedded in the ICMPv6 data segment of the probe message. By monitoring the forwarded messages on the controlled host, exploitable IPv6 tunnel routing nodes within the target network can be identified.
[0082] Then, a new probe message is sent from the controlled host to the available IPv6 tunnel routing node discovered in the above step. This message is similar to the originally sent message, but the outer IPv4 source address is forged to be an address within the tested network. Specifically, if the IPv4 address of the tunnel routing node is abcd, the source address of the probe message is set to abce, where e = (d+1) mod 255. By observing whether the forwarded message can still be received on the controlled host, it is determined whether the message with the forged source address has successfully entered the target network, thereby evaluating the target network's ISAV deployment under IPv4.
[0083] When the above-mentioned probe message is decapsulated and the inner part is forwarded, the inner IPv6 source address will become the source address of the new message. In order for the forwarded message to successfully reach the controlled host, the selection of the address should follow the following principles: 1) The address cannot use the address inside the network where the controlled host is located to avoid being affected by the ISAV of the network where the controlled host is located; 2) The address should use the IPv6 address of the IPv6 tunnel routing node as much as possible (if known) to avoid being affected by the OSAV of the network under test. The third part of this solution introduces a method for collecting IPv4-IPv6 address pairs of IPv6 tunnel routing nodes to obtain the IPv6 address of the tunnel routing node; when it cannot be obtained, the address uses any pure IPv6 address of the internal address of the network where the non-controlled host is located. In the two probe messages sent before and after, the address should use the same value to constitute a strict control experiment to avoid introducing deviations.
[0084] Second: OSAV deployment measurement under IPv6.
[0085] The measurement of OSAV deployment under IPv6 utilizes the method of sending packets on the IPv6 tunnel routing node as the remote measurement point. The process is as follows: Figure 4 As shown, Figure 4 The meaning of each parameter in Figure 3 The same as in , I will not repeat it here. Figure 4 , a probe message with a double-layer header structure can be sent from the controlled node to all IPv4 addresses in the network under test to discover available IPv6 tunnel routing nodes. The outer IPv4 source address of the probe message is the real address of the controlled host to ensure that the message successfully reaches the destination. The inner IPv6 destination address is the IPv6 address of the controlled host. When the IPv6 tunnel routing node in the network receives the probe message, it will decapsulate the message and forward the inner part. By setting the inner IPv6 source address to the real IPv6 address and the forged IPv6 address of the tunnel routing node respectively, the tunnel routing node can send normal traffic and forged traffic respectively. By checking at the controlled host whether these flows can leave the network under test and be received, the OSAV deployment status of the target network under IPv6 can be determined.
[0086] Using the method described in Section 3 below to collect IPv4-IPv6 address pairs for IPv6 tunnel routing nodes, the true IPv6 address of the tunnel routing node can be obtained. The forged IPv6 address is an address in an IPv6 prefix that does not belong to the autonomous system in which the address resides and is not within the network where the controlled host resides, to avoid being affected by the ISAV of the controlled host's network. If the true IPv6 address of the tunnel routing node cannot be obtained, the address in the IPv6 prefix of the autonomous system in which the node's IPv4 address resides is used.
[0087] Third: IPv4-IPv6 address pair collection.
[0088] As mentioned above, this application collects IPv4-IPv6 address pairs of IPv6 tunnel routing nodes to expand the coverage of the SAV measurement method. The process of collecting address pairs is as follows: Figure 5 As shown in the figure, the meaning of each parameter is the same as Figure 3The process is similar to that described in [1] and will not be repeated here. First, a probe message can be sent from the controlled host to the tunnel routing node. This message is an ICMPv6 Echo Request message encapsulated in an IPv4 message. The outer IPv4 source address of the message is the real IPv4 address of the controlled host, the inner IPv6 source address is the real IPv6 address of the controlled host, and the destination address is a pure IPv6 address that does not belong to the network of the controlled host or the network of the tunnel routing node. The Hop Limit field of the inner header is set to 1. When this probe message is transmitted in the IPv4 Internet, the Hop Limit field remains unchanged because the inner header is considered part of the payload. Once the message reaches the IPv6 tunnel routing node and is decapsulated, the Hop Limit field is reduced to 0. At this point, the IPv6 tunnel routing node will send an ICMPv6 Time Exceeded error message to the controlled host. The source address of this error message is the IPv6 address of the tunnel routing node. The controlled measurement host may receive the error message and record the IPv4-IPv6 address pair of the IPv6 tunnel routing node.
[0089] It can be seen that the source address verification deployment detection method based on IPv6 tunnel routing nodes provided in the present application can use the IPv6 tunnel routing nodes that are ubiquitous in the network to measure the ISAV deployment status under IPv4 and the OSAV deployment status under IPv6 without deploying measurement points in the target network, and has a wider coverage range; at the same time, the measurement of the source address verification deployment status is conducive to discovering potential security threats in the network. The source address verification deployment detection method based on IPv6 tunnel routing nodes provided in the present application obtained the ISAV deployment status of 12,417 autonomous systems under IPv4 and the OSAV deployment status of 2,979 autonomous systems under IPv6 through measurements within the Internet. The measurement method has high effectiveness and high coverage; moreover, the use of IPv6 tunnel technology to detect SAV deployment status can provide important data support for the study of network security situation, and can effectively identify networks that are vulnerable to source address spoofing attacks, which is beneficial for network managers to promptly discover security issues in the network, verify the effectiveness of the network's source address verification strategy, improve the accuracy and response speed of related defense measures, promote the optimization of network management costs, and enhance the comprehensive protection and management capabilities of the network, and improve the credibility of the network environment.
[0090] In order to implement the above embodiment, the present application also proposes a source address verification and deployment detection device based on IPv6 tunnel routing nodes.
[0091] Figure 6 A schematic diagram of the structure of a source address verification deployment detection device based on IPv6 tunnel routing nodes provided in an embodiment of the present application.
[0092] like Figure 6 As shown, the source address verification deployment detection device 600 based on the IPv6 tunnel routing node includes:
[0093] A first message sending module 610 is configured to send a first detection message from the controlled host to all IPv4 addresses in the tested network; wherein the outer IPv4 source address of the first detection message is the real IPv4 address of the controlled host, the inner IPv6 source address is a pure IPv6 address, and the inner IPv6 destination address is the IPv6 address of the controlled host;
[0094] A first forwarding module 620 is configured to decapsulate an inner portion of the first detection message and forward the inner portion to the controlled host after the IPv6 tunnel routing node in the tested network receives the first detection message;
[0095] A determination module 630 is configured to determine, through the controlled host, a target IPv6 tunnel routing node in the tested network based on the inner portion of the message;
[0096] A second message sending module 640 is configured to send a second detection message to the target IPv6 tunnel routing node through the controlled host; wherein the outer IPv4 source address of the second detection message is an address inside the measured network;
[0097] A second forwarding module 650 is configured to forward the inner portion of the second detection message to the controlled host after the target IPv6 tunnel routing node receives the second detection message;
[0098] The deployment detection module 660 is used to determine the target network's IPv4 source address verification ISAV deployment status based on the reception of messages forwarded by the target IPv6 tunnel routing node through the controlled host.
[0099] In order to implement the above embodiments, the present application also proposes an electronic device, comprising: a processor, and a memory communicatively connected to the processor; the memory stores computer-executable instructions; the processor executes the computer-executable instructions stored in the memory to implement the method provided by the above embodiments.
[0100] In order to implement the above embodiments, the present application also proposes a computer-readable storage medium, in which computer-executable instructions are stored. When the computer-executable instructions are executed by a processor, they are used to implement the methods provided by the above embodiments.
[0101] In order to implement the above embodiments, the present application also proposes a computer program product, including a computer program, which implements the methods provided by the above embodiments when executed by a processor.
[0102] The collection, storage, use, processing, transmission, provision and disclosure of user personal information involved in this application are in compliance with relevant laws and regulations and do not violate public order and good morals.
[0103] It is important to note that personal information collected from users should be used for legitimate and reasonable purposes and should not be shared or sold beyond these legitimate uses. Furthermore, such collection / sharing should be conducted only after receiving the user's informed consent, including but not limited to notifying the user to read the user agreement / user notice and sign an agreement / authorization that includes the relevant user information before using the feature. Furthermore, any necessary steps must be taken to safeguard and secure access to such personal information and ensure that others with access to personal information comply with its privacy policy and procedures.
[0104] This application contemplates providing implementation options for users to selectively block the use or access of personal information data. Specifically, this application contemplates providing hardware and / or software to prevent or block access to such personal information data. Risks can be minimized by limiting data collection and deleting data once it is no longer needed. Furthermore, where applicable, such personal information can be de-identified to protect user privacy.
[0105] In the descriptions of the foregoing embodiments, the reference terms "one embodiment", "some embodiments", "example", "specific example", or "some examples" mean that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present application. In this specification, the schematic expressions of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described may be combined in any one or more embodiments or examples in a suitable manner. In addition, those skilled in the art may combine and combine the different embodiments or examples described in this specification and the features of the different embodiments or examples, unless they are mutually inconsistent.
[0106] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of the technical features being referred to. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one of such features. Throughout the description of this application, "plurality" means at least two, for example, two, three, etc., unless otherwise specifically defined.
[0107] Any process or method description in a flowchart or otherwise described herein may be understood to represent a module, segment or portion of code comprising one or more executable instructions for implementing the steps of a custom logical function or process, and the scope of the preferred embodiments of the present application includes alternative implementations in which functions may be performed out of the order shown or discussed, including performing functions in a substantially simultaneous manner or in the reverse order depending on the functions involved, which should be understood by those skilled in the art to which the embodiments of the present application belong.
[0108] The logic and / or steps represented in the flowcharts or otherwise described herein, for example, can be considered as a sequenced list of executable instructions for implementing the logical functions, and can be embodied in any computer-readable medium for use by, or in conjunction with, an instruction execution system, apparatus, or device (e.g., a computer-based system, a system including a processor, or other system that can fetch and execute instructions from an instruction execution system, apparatus, or device). For purposes of this specification, a "computer-readable medium" can be any device that can contain, store, communicate, propagate, or transport a program for use by, or in conjunction with, an instruction execution system, apparatus, or device. More specific examples (a non-exhaustive list) of computer-readable media include the following: an electrical connection with one or more wires (electronic devices), a portable computer disk cartridge (magnetic device), random access memory (RAM), read-only memory (ROM), erasable and programmable read-only memory (EPROM or flash memory), fiber optic devices, and a portable compact disc read-only memory (CDROM). Furthermore, the computer-readable medium may even be paper or other suitable medium on which the program is printed, since the program may be obtained electronically, for example, by optically scanning the paper or other medium and then editing, interpreting or processing it in another suitable manner if necessary, and then storing it in a computer memory.
[0109] It should be understood that various parts of the present application can be implemented using hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented using software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented using hardware, as in another embodiment, any one of the following technologies known in the art or a combination thereof can be used to implement: a discrete logic circuit having a logic gate circuit for implementing a logic function on a data signal, an application-specific integrated circuit having a suitable combination of logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc.
[0110] Those skilled in the art will understand that all or part of the steps in the method of the above embodiment can be completed by instructing related hardware through a program, and the program can be stored in a computer-readable storage medium. When the program is executed, it includes one or a combination of the steps of the method embodiment.
[0111] In addition, the functional units in the various embodiments of the present application may be integrated into a processing module, or each unit may exist physically separately, or two or more units may be integrated into a module. The above-mentioned integrated module may be implemented in the form of hardware or in the form of a software functional module. If the integrated module is implemented in the form of a software functional module and sold or used as an independent product, it may also be stored in a computer-readable storage medium.
[0112] The storage medium mentioned above may be a read-only memory, a magnetic disk, or an optical disk, etc. Although the embodiments of the present application have been shown and described above, it is understood that the above embodiments are exemplary and should not be construed as limiting the present application. Persons skilled in the art may make changes, modifications, substitutions, and variations to the above embodiments within the scope of the present application.
Claims
1. A source address verification deployment detection method based on IPv6 tunnel routing nodes, characterized in that: include: Send a first probe message from the controlled host to all IPv4 addresses in the tested network; wherein the outer IPv4 source address of the first probe message is the real IPv4 address of the controlled host, the inner IPv6 source address is a pure IPv6 address, and the inner IPv6 destination address is the IPv6 address of the controlled host; After receiving the first detection message, the IPv6 tunnel routing node in the tested network decapsulates the inner portion of the first detection message and forwards the message to the controlled host; Determine, by the controlled host, a target IPv6 tunnel routing node in the network under test based on the inner portion of the message; Sending a second detection message to the target IPv6 tunnel routing node through the controlled host; wherein the outer IPv4 source address of the second detection message is an address inside the measured network; After the target IPv6 tunnel routing node receives the second detection message, forwarding the inner part of the second detection message to the controlled host; The controlled host determines the target network's entry source address under IPv4 to verify the ISAV deployment status based on the message reception status forwarded by the target IPv6 tunnel routing node.
2. The method according to claim 1, characterized in that in, The IPv4 address information of the destination address is embedded in the ICMPv6 data segment of the first detection message.
3. The method according to claim 2, characterized in that in, The determining, by the controlled host based on the inner portion of the message, a target IPv6 tunnel routing node in the tested network includes: The controlled host determines the target IPv6 tunnel routing node in the tested network based on the inner portion of the message and the embedded IPv4 address information.
4. The method according to claim 1, wherein Also includes: Sending a third probe message from the controlled node to all IPv4 addresses in the measured network; wherein the third probe message is a probe message with a double-layer header structure, the outer IPv4 source address of the third probe message is the real address of the controlled host, and the inner IPv6 destination address is the IPv6 address of the controlled host; After receiving the third detection message, the IPv6 tunnel routing node in the tested network decapsulates the inner portion of the third detection message; Modify the IPv6 source address of the inner portion of the third detection message to the real IPv6 address and the forged IPv6 address of the IPv6 tunnel routing node, respectively, and forward the inner portion of the third detection message after the address is modified to the controlled host; The controlled host determines the outbound source address of the tested network under IPv6 based on the reception of the inner portion of the third detection message after the address is modified, and verifies the OSAV deployment status.
5. The method according to claim 2, characterized in that Also includes: A fourth detection message is sent from the controlled host to the IPv6 tunnel routing node; wherein the fourth detection message is an ICMPv6 Echo Request message encapsulated in an IPv4 message, the outer IPv4 source address is the real IPv4 address of the controlled host, the inner IPv6 source address is the real IPv6 address of the controlled host, the inner IPv6 destination address is a pure IPv6 address that does not belong to the network where the controlled host is located and does not belong to the network where the IPv6 tunnel routing node is located, and the Hop Limit field of the inner header is set to a preset value; When the fourth probe message arrives at the IPv6 tunnel routing node and is decapsulated, the HopLimit field is modified to the preset value -1, and an error message is sent to the controlled host through the IPv6 tunnel routing node; wherein the source address of the error message is the IPv6 address of the IPv6 tunnel routing node; When the controlled host receives the error message, the IPv4-IPv6 address pair of the IPv6 tunnel routing node is recorded.
6. The method according to claim 5, characterized in that in, The error message type is ICMPv6 TimeExceeded.
7. A source address verification and deployment detection device based on IPv6 tunnel routing nodes, characterized in that: include: A first message sending module is used to send a first detection message from the controlled host to all IPv4 addresses in the measured network; wherein the outer IPv4 source address of the first detection message is the real IPv4 address of the controlled host, the inner IPv6 source address is a pure IPv6 address, and the inner IPv6 destination address is the IPv6 address of the controlled host; A first forwarding module is configured to decapsulate an inner portion of the first detection message and forward the inner portion of the first detection message to the controlled host after the IPv6 tunnel routing node in the measured network receives the first detection message; A determination module, configured to determine, through the controlled host, a target IPv6 tunnel routing node in the tested network based on the inner portion of the message; A second message sending module is used to send a second detection message to the target IPv6 tunnel routing node through the controlled host; wherein the outer IPv4 source address of the second detection message is an address inside the measured network; A second forwarding module is configured to forward an inner portion of the second detection message to the controlled host after the target IPv6 tunnel routing node receives the second detection message; The deployment detection module is used to determine the target network's IPv4 source address verification ISAV deployment status through the controlled host according to the message reception status forwarded by the target IPv6 tunnel routing node.
8. An electronic device, characterized in that: include: at least one processor; as well as a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method according to any one of claims 1 to 6.
9. A non-transitory computer-readable storage medium storing computer instructions, characterized in that: The computer-readable storage medium stores computer-executable instructions, and the computer-executable instructions are used to enable the computer to execute the method according to any one of claims 1 to 6.
10. A computer program product, characterized in that The invention comprises a computer program, which is capable of performing the method according to any one of claims 1 to 6 when being executed by a processor.