Photo by Warren Umoh on Unsplash

Photo by Warren Umoh on Unsplash

Safeguards and First-Hop Security for IPv6

Invisible Threat

Article from ADMIN 95/2026
By
Both IPv4 and IPv6 are implemented by default on all operating systems. Some IPv6 processes occur independent of user input or configurations, which can open up dangerous vulnerabilities on the network. We explain how you can set up safeguards and establish first-hop security.

Most organizations have not yet taken any steps to secure their IPv6-capable nodes, and most IT departments do not genuinely understand how IPv6 works on a LAN or how it differs from the IPv4 protocol. You cannot effectively protect yourself against something you don't understand; moreover, IPv6 has some specific functional differences from IPv4 that dictate changes to the defense strategy against LAN threats.

In most cases, admins fail to implement specific security measures to protect IPv4 Address Resolution Protocol (ARP) or Dynamic Host Configuration Protocol (DHCP) traffic in access networks. However, many LAN-based attacks targeting IPv6 exploit vulnerabilities that are similar to – or exactly the same as – those exploited by IPv4 threats. If no IPv4 LAN protections are in place, it is pointless to demand higher security standards for IPv6 neighbor discovery.

Threats Posed by IPv6 NDP

The IPv6 Neighbor Discovery Protocol (NDP; RFC 4861) facilitates communication among IPv6 nodes and uses the Internet Control Message Protocol (ICMPv6) and link-local multicast communication to perform functions similar to those of IPv4's ARP. Attacks on the protocol typically target local physical or virtual connections. To do so, the attacker must have physical access to the local network or must have compromised a system on the LAN and brought it under their control.

Although attempting to guess IPv6 addresses used by local nodes with brute-force techniques is impractical when scouting for IPv6-capable nodes on the LAN, a resourceful hacker can use some methods to speed up the process of locating these nodes. Some of these methods are covert and silent, and others leave traces.

A locally connected attacker can exploit a number of known LAN vulnerabilities (see, e.g., RFC 6583 [1]). For example, a link-local attacker can generate


...

Use one of the options below to read the full article

Buy this article as PDF

Download Article PDF now with Express Checkout
Price $2.95
(incl. VAT)

Buy ADMIN Magazine

Related content

  • Access Anywhere with Mobile IPv6

    IPv6 includes Mobile IPv6, a new standard for communication with mobile devices, which ensures permanent accessibility regardless of your current location. In this article, we provide an overview of Mobile IPv6 functionality.

  • Accessibility wherever you are with Mobile IPv6
    IPv6 includes Mobile IPv6, a new standard for communication with mobile devices, which ensures permanent accessibility regardless of your current location. In this article, we provide an overview of Mobile IPv6 functionality.
  • Understanding Layer 2 switch port security
    What happens when an intruder with a laptop parks at an empty cubicle and attaches to your local network? If you don't want to find out, it might be time to think about implementing some switch port security.
  • Neglected IPv6 features endanger the LAN
    IPv6 is establishing itself in everyday IT life, and all modern operating systems from Windows, through Mac OS X, to Linux have it on board; but if you let IPv6 introduce itself into your environment, you could be in for some unpleasant surprises.
  • Monitoring IPv6 with Wireshark
    Although IPv6 is still waiting for its big breakthrough, on many networks, admins can no longer avoid it. Luckily, the free Wireshark tool can provide valuable error analysis.
comments powered by Disqus