IPv6 Extension Header Reputation Filtering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
IPv6 extension headers, due to their variable and undefined nature, pose security concerns as they can be misused to crash traversing devices, leading to issues like fuzzing and overflow attacks, and existing security measures do not effectively examine or process these headers beyond the destination node.
Innovation Solution
Traversing devices maintain reputation information on senders based on security checks and selectively block, rate limit, or quarantine IPv6 packets or fragments with nonconformity issues, and perform normalization, security checks, and countermeasures such as blocking or modifying headers to prevent misuse.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traversing devices examine and process IPv6 extension headers, then security is improved, but device complexity and processing overhead increase
Solution Approach 1:
The patent applies preliminary action by performing security checks on IPv6 extension headers at traversing devices (routers, firewalls) before packets reach their destination. The system proactively examines extension headers, validates their conformity to specifications, and takes preventive measures against potential attacks, rather than waiting for attacks to occur or relying solely on destination nodes to detect issues.
Solution Approach 2:
The patent segments the security verification process into distinct components: identifying extension headers in IPv6 packets, validating each extension header against RFC specifications, maintaining reputation information for senders, and applying appropriate countermeasures. This segmentation allows the complex security function to be implemented in manageable steps without overwhelming device complexity.
2Device complexity
If IPv6 extension headers are not examined by traversing devices, then device complexity is reduced, but security vulnerabilities increase due to fuzzing and overflow attacks
Solution Approach 1:
The patent introduces traversing devices as intermediaries between packet senders and destination nodes. These intermediaries perform security verification of extension headers, acting as a protective layer that filters out malicious packets before they can exploit vulnerabilities at destination nodes. The intermediary approach maintains simplicity at endpoints while ensuring security through centralized validation.
Solution Approach 2:
The patent applies preliminary anti-action by implementing security measures that prevent attacks before they can succeed. The system identifies and blocks non-conformant extension headers that could be used for fuzzing or overflow attacks, thereby neutralizing threats before they reach vulnerable systems. Reputation tracking further reinforces this by learning from past attacks to preempt future ones.
3Reliability
If all IPv6 packets with extension headers are blocked, then security is improved, but network productivity decreases due to legitimate traffic being interrupted
Solution Approach 1:
The patent applies local quality by treating different IPv6 packets differently based on their specific characteristics. Rather than applying a uniform block policy to all packets with extension headers, the system validates each packet's extension headers individually against RFC specifications and sender reputation. Legitimate packets that pass validation are allowed through, while only non-conformant packets are blocked, ensuring security without unnecessarily disrupting network productivity.
Solution Approach 2:
The patent implements feedback mechanisms through reputation tracking, where the system learns from observed sender behavior and adjusts its security responses accordingly. By monitoring which senders have history of sending non-conformant packets, the system can make informed decisions about whether to allow or block future packets from those sources, optimizing the balance between security and network productivity based on actual observed patterns rather than blanket rules.
4Speed
If extension headers are allowed to pass without verification, then network speed is maintained, but traversing devices become vulnerable to crashes from malformed headers
Solution Approach 1:
The patent applies partial action by performing security verification only on the extension header portion of IPv6 packets, rather than examining every single bit of every packet. The validation focuses specifically on the structure and conformity of extension headers to RFC specifications, allowing legitimate traffic to pass through quickly while intercepting and blocking only the malformed headers that could cause device crashes. This targeted approach minimizes the impact on network speed while ensuring device stability.
Data Source
AI summary
Methods and systems for selectively blocking, allowing and/or reformatting IPv6 headers by traversing devices are provided. According to one embodiment, reputation information regarding observed senders of Internet Protocol (IP) version 6 (IPv6) packets and packet fragments is maintained by a traversing device based on conformity or nonconformity of extension headers contained within the IPv6 packets with respect to a set of security checks performed by the traversing device. When an IPv6 packet or packet fragment is received from a particular source IP address indicated by the reputation information to be associated with one or more nonconformity issues, then dropping, rate limiting or quarantining, by the traversing device, the IPv6 packet or the packet fragment.


