Your Router is My Prober: Measuring IPv6 Networks via ICMP Rate Limiting Side Channels

10/24/2022
by   Long Pan, et al.
0

Active Internet measurements face challenges when some measurements require many remote vantage points. In this paper, we propose a novel technique for measuring remote IPv6 networks via side channels in ICMP rate limiting, a required function for IPv6 nodes to limit the rate at which ICMP error messages are generated. This technique, iVantage, can to some extent use 1.1M remote routers distributed in 9.5k autonomous systems and 182 countries as our "vantage points". We apply iVantage to two different, but both challenging measurement tasks: 1) measuring the deployment of inbound source address validation (ISAV) and 2) measuring reachability between arbitrary Internet nodes. We accomplish these two tasks from only one local vantage point without controlling the targets or relying on other services within the target networks. Our large-scale ISAV measurements cover  50 systems and find  79 large-scale measurement study of IPv6 ISAV to date. Our method for reachability measurements achieves over 80 we perform an Internet-wide measurement of the ICMP rate limiting implementations, present a detailed discussion on ICMP rate limiting, particularly the potential security and privacy risks in the mechanism of ICMP rate limiting, and provide possible mitigation measures. We make our code available to the community.

READ FULL TEXT

page 1

page 10

research
01/29/2019

An Internet Heartbeat

Obtaining sound inferences over remote networks via active or passive me...
research
04/10/2023

Measuring and Evading Turkmenistan's Internet Censorship: A Case Study in Large-Scale Measurements of a Low-Penetration Country

Since 2006, Turkmenistan has been listed as one of the few Internet enem...
research
01/22/2019

Hidden Treasures - Recycling Large-Scale Internet Measurements to Study the Internet's Control Plane

Internet-wide scans are a common active measurement approach to study th...
research
07/16/2019

Measuring I2P Censorship at a Global Scale

The prevalence of Internet censorship has prompted the creation of sever...
research
03/12/2020

SMap: Internet-wide Scanning for Ingress Filtering

To protect from attacks, networks need to enforce ingress filtering. Des...
research
07/06/2011

On the information-theoretic structure of distributed measurements

The internal structure of a measuring device, which depends on what its ...
research
12/19/2019

ODIN: Tamper-Resistant Round Trip Time Measurement for Distributed Systems

Measuring round trip time (RTT) in a hostile network is an unsolved prob...

Please sign up or login with your details

Forgot password? Click here to reset