Opening Pandora’s Packet: Expose IPv6 Implementations Vulnerabilities Using Differential Fuzzing


연구 분야: Strategies



학회: International Conference on Applied Cryptography and Network Security


초록

IPv6 is the next generation of the Internet Protocol that is being deployed around the world to replace IPv4. In the design of IPv6, extension headers allow the protocol to be flexible, enabling optional features, such as fragmentation or encryption. However, the complexity of this design often leads to vulnerabilities that can affect millions of hosts worldwide. In this paper, we propose a new methodology that exploits differential fuzzing to uncover and analyze vulnerabilities in IPv6 network stack implementations. We run a thorough set of experiments to validate the methodology on several operating systems, such as Windows, Linux, and FreeBSD, uncovering two firewall policies bypass and multiple fingerprinting possibilities. The results highlight the danger of vulnerabilities at this level of the network stack and underscore the importance of testing IPv6 as it becomes the core part of the Internet. Researchers and implementers can use our proposed methodology to look for security issues in other operating systems in a semi-automatic way.


Author Profile
Enrico Bassetti

Delft University of Technology Delft The Netherlands

Netherlands
Author Profile
Edoardo Di Paolo

Sapienza University of Rome Rome Italy

Italy
Author Profile
Francesco Drago

University of Padua Padua Italy

Italy

📄 논문 정보

발행 연도 2025년
인용수 0
출판 국가 Italy, Netherlands
사이트 Springer
좋아요 수 0

연관 논문 목록 (157건)