IPv6 Extension Header Reputation Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IPv6 extension headers, due to their variable and undefined nature, pose security concerns as they can be misused to crash traversing devices, leading to issues like fuzzing and overflow attacks, and existing security measures do not effectively examine or process these headers beyond the destination node.

Innovation Solution

Traversing devices maintain reputation information on senders based on security checks and selectively block, rate limit, or quarantine IPv6 packets or fragments with nonconformity issues, and perform normalization, security checks, and countermeasures such as blocking or modifying headers to prevent misuse.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traversing devices examine and process IPv6 extension headers, then security is improved, but device complexity and processing overhead increase

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by performing security checks on IPv6 extension headers at traversing devices (routers, firewalls) before packets reach their destination. The system proactively examines extension headers, validates their conformity to specifications, and takes preventive measures against potential attacks, rather than waiting for attacks to occur or relying solely on destination nodes to detect issues.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the security verification process into distinct components: identifying extension headers in IPv6 packets, validating each extension header against RFC specifications, maintaining reputation information for senders, and applying appropriate countermeasures. This segmentation allows the complex security function to be implemented in manageable steps without overwhelming device complexity.

Inventive Principle:
Principle #1Segmentation

2Device complexity

If IPv6 extension headers are not examined by traversing devices, then device complexity is reduced, but security vulnerabilities increase due to fuzzing and overflow attacks

Engineering Contradiction:
Improvedevice complexityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces traversing devices as intermediaries between packet senders and destination nodes. These intermediaries perform security verification of extension headers, acting as a protective layer that filters out malicious packets before they can exploit vulnerabilities at destination nodes. The intermediary approach maintains simplicity at endpoints while ensuring security through centralized validation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies preliminary anti-action by implementing security measures that prevent attacks before they can succeed. The system identifies and blocks non-conformant extension headers that could be used for fuzzing or overflow attacks, thereby neutralizing threats before they reach vulnerable systems. Reputation tracking further reinforces this by learning from past attacks to preempt future ones.

Inventive Principle:
Principle #9Preliminary anti-action

3Reliability

If all IPv6 packets with extension headers are blocked, then security is improved, but network productivity decreases due to legitimate traffic being interrupted

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork productivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies local quality by treating different IPv6 packets differently based on their specific characteristics. Rather than applying a uniform block policy to all packets with extension headers, the system validates each packet's extension headers individually against RFC specifications and sender reputation. Legitimate packets that pass validation are allowed through, while only non-conformant packets are blocked, ensuring security without unnecessarily disrupting network productivity.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements feedback mechanisms through reputation tracking, where the system learns from observed sender behavior and adjusts its security responses accordingly. By monitoring which senders have history of sending non-conformant packets, the system can make informed decisions about whether to allow or block future packets from those sources, optimizing the balance between security and network productivity based on actual observed patterns rather than blanket rules.

Inventive Principle:
Principle #23Feedback

4Speed

If extension headers are allowed to pass without verification, then network speed is maintained, but traversing devices become vulnerable to crashes from malformed headers

Engineering Contradiction:
Improvenetwork speedVSAvoiddevice stability
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent applies partial action by performing security verification only on the extension header portion of IPv6 packets, rather than examining every single bit of every packet. The validation focuses specifically on the structure and conformity of extension headers to RFC specifications, allowing legitimate traffic to pass through quickly while intercepting and blocking only the malformed headers that could cause device crashes. This targeted approach minimizes the impact on network speed while ensuring device stability.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10057213B2Examining and controlling IPv6 extension headers
Publication Date: 2018.08.21 FORTINET INC
  • US10057213B2 patent drawing
  • US10057213B2 patent drawing
  • US10057213B2 patent drawing

AI summary

Methods and systems for selectively blocking, allowing and/or reformatting IPv6 headers by traversing devices are provided. According to one embodiment, reputation information regarding observed senders of Internet Protocol (IP) version 6 (IPv6) packets and packet fragments is maintained by a traversing device based on conformity or nonconformity of extension headers contained within the IPv6 packets with respect to a set of security checks performed by the traversing device. When an IPv6 packet or packet fragment is received from a particular source IP address indicated by the reputation information to be associated with one or more nonconformity issues, then dropping, rate limiting or quarantining, by the traversing device, the IPv6 packet or the packet fragment.