Kirin: Hitting the Internet with Millions of Distributed IPv6 Announcements

10/19/2022
by   Lars Prehn, et al.
0

The Internet is a critical resource in the day-to-day life of billions of users. To support the growing number of users and their increasing demands, operators have to continuously scale their network footprint – e.g., by joining Internet Exchange Points – and adopt relevant technologies – such as IPv6. IPv6, however, has a vastly larger address space compared to its predecessor, which allows for new kinds of attacks on the Internet routing infrastructure. In this paper, we present Kirin: a BGP attack that sources millions of IPv6 routes and distributes them via thousands of sessions across various IXPs to overflow the memory of border routers within thousands of remote ASes. Kirin's highly distributed nature allows it to bypass traditional route-flooding defense mechanisms, such as per-session prefix limits or route flap damping. We analyze the theoretical feasibility of the attack by formulating it as a Integer Linear Programming problem, test for practical hurdles by deploying the infrastructure required to perform a small-scale Kirin attack using 4 IXPs, and validate our assumptions via BGP data analysis, real-world measurements, and router testbed experiments. Despite its low deployment cost, we find Kirin capable of injecting lethal amounts of IPv6 routes in the routers of thousands of ASes.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
06/22/2020

IXmon: Detecting and Analyzing DRDoS Attacks at Internet Exchange Points

Distributed reflective denial of service (DRDoS) attacks are a popular c...
research
07/03/2021

Too Expensive to Attack: Enlarge the Attack Expense through Joint Defense at the Edge

The distributed denial of service (DDoS) attack is detrimental to busine...
research
05/04/2020

Preventing Time Synchronization in NTP's Broadcast Mode

Network Time Protocol (NTP) is used by millions of hosts in Internet tod...
research
11/12/2019

O Peer, Where Art Thou? Uncovering Remote Peering Interconnections at IXPs

Internet eXchange Points (IXPs) are Internet hubs that mainly provide th...
research
08/06/2020

Internet-Scale Video Streaming over NDN

Research in Information-Centric Networking (ICN) and Named Data Networki...
research
06/11/2020

Peerlock: Flexsealing BGP

BGP route leaks frequently precipitate serious disruptions to interdomai...
research
08/29/2020

Tangled: A Cooperative Anycast Testbed

Anycast routing is an area of studies that has been attracting interest ...

Please sign up or login with your details

Forgot password? Click here to reset