Stories
Slash Boxes
Comments

SoylentNews is people

posted by Fnord666 on Sunday March 04 2018, @06:39PM   Printer-friendly
from the knock-knock dept.

Network guru Wesley George noticed the strange traffic earlier this week as part of a larger attack on a DNS server in an effort to overwhelm it. He was taking packet captures of the malicious traffic as part of his job at Neustar's SiteProtect DDoS protection service when he realized there were "packets coming from IPv6 addresses to an IPv6 host."

The attack wasn't huge – unlike this week's record-breaking 1.35Tbps attack on GitHub – and it wasn't using a method that is exclusive to IPv6, but it was sufficiently unusual and worrying to flag to the rest of his team.

Computers behind 1,900 IPv6 addresses were attacking the DNS server as part of a larger army of commandeered systems, mostly using IPv4 addresses on the public internet. Anyone running an IPv6 network needs to, therefore, ensure they have the same level of network security and mitigation tools in place as their IPv4 networks – and fast.

"The risk is that if you don't have IPv6 as part of your threat model, you could get blindsided," Neustar's head of research and development Barrett Lyon told us.

[...] Adding to the list of potential IPv6 security issues are: the fact that some mitigation tools only work with IPv4 (often thanks to hard-coded addresses written into their code) – or are put into IPv4 and only later ported across to IPv6; that a lot of IPv6 networking is being done in software (rather than hardware) opening up many more potential security holes; and that the expansion of packet headers in the IPv6 protocols creates potential new attack vectors.

[...] George hypothesized that one big future problem could be if a network is hit with a combination of IPv4 and IPv6 attack traffic – as happened in this case. A sysadmin could pull out all the normal mitigation tools but only kill off the IPv4 traffic, leaving the network under attack and the person in charge unable to figure out why.

Thanks to the dual-stack system most people are using to rollout IPv6 alongside their existing systems, Lyon also worries that an IPv6 attack could compromise the routers and switches used to run the networks side-by-side and so attack IPv4 networks through the backdoor.

This week's attack is "only the tip of the iceberg", Lyon said. His hope is this it serves as a wake-up call for sysadmins to apply best practices to IPv6 networks, and argues that "anything you do in the IPv4 world, you should be doing in the IPv6 world."

It's fair to say he is not confident that people will learn the lesson ahead of time though. "People don't tend to think of security as a priority for later," said Lyon. "It doesn't come until there's a crisis."


Original Submission

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 2, Touché) by Anonymous Coward on Sunday March 04 2018, @08:52PM (1 child)

    by Anonymous Coward on Sunday March 04 2018, @08:52PM (#647719)

    He didn't know what the weather was, as he was sitting in his small, dark basement as always, posting his fantasies about women-killers. He just had finished yet another post, as he noticed some movement behind him.

    He turned around, and he immediately recognized the biggest horror he could imagine. Behind him was the object of his greatest and most secret fear. He got into panic from the mere view. One of them had found him and his hideout, managed to get past all his security measures, which consisted of an old, rusty lock that every five-year-old would have broken even accidentally, and now finally the source of all his fear had entered his basement. Behind him was a woman.

    She didn't have to do anything at all, since he got a heart attack just from viewing her. She watched until he was dead, and then she went away smiling. The source of those troll posts had finally been eliminated.

    Starting Score:    0  points
    Moderation   +2  
       Offtopic=2, Informative=1, Touché=3, Total=6
    Extra 'Touché' Modifier   0  

    Total Score:   2  
  • (Score: 3, Funny) by Anonymous Coward on Sunday March 04 2018, @09:09PM

    by Anonymous Coward on Sunday March 04 2018, @09:09PM (#647727)

    Mom?