Routing Loop Attack Using IPv6 Automatic Tunnels: Problem Statement and Proposed Mitigations
RFC 6324, “Routing Loop Attack Using IPv6 Automatic Tunnels: Problem Statement and Proposed Mitigations”, is an Informational document published in August 2011 by G. Nakibly, F. Templin. The canonical text is published by the RFC Editor.
Abstract
This document is concerned with security vulnerabilities in IPv6-in- IPv4 automatic tunnels. These vulnerabilities allow an attacker to take advantage of inconsistencies between the IPv4 routing state and the IPv6 routing state. The attack forms a routing loop that can be abused as a vehicle for traffic amplification to facilitate denial- of-service (DoS) attacks. The first aim of this document is to inform on this attack and its root causes. The second aim is to present some possible mitigation measures. It should be noted that at the time of this writing there are no known reports of malicious attacks exploiting these vulnerabilities. Nonetheless, these vulnerabilities can be activated by accidental misconfiguration. This document is not an Internet Standards Track specification; it is published for informational purposes.
What “Informational” means
Published for the general information of the community. It does not define an IETF standard and carries no standards-track status.
The canonical text of RFC 6324 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 6323 Sender RTT Estimate Option for the Datagram Congestion Control Protocol
- RFC 6325 Routing Bridges : Base Protocol Specification
- RFC 6322 Datatracker States and Annotations for the IAB, IRTF, and Independent Submission Streams
- RFC 6326 Transparent Interconnection of Lots of Links Use of IS-IS
- RFC 6321 xCal: The XML Format for iCalendar
- RFC 6327 Routing Bridges : Adjacency
- RFC 6320 Protocol for Access Node Control Mechanism in Broadband Networks
- RFC 6328 IANA Considerations for Network Layer Protocol Identifiers