Logo image
Towards a secure and accessible internet over IPV6
Dissertation   Open access

Towards a secure and accessible internet over IPV6

Hammas Bin Tanveer
University of Iowa
Doctor of Philosophy (PhD), University of Iowa
Spring 2025
DOI: 10.25820/etd.007969
pdf
Thesis_hammas_minor_fixes2.00 MBDownloadView
Open Access Free to read and download

Abstract

Internet protocol version 6 (IPv6) was introduced to curb a fundamental scalability issue facing the internet; the IP exhaustion problem. IPv6 tackled this by introducing a significantly larger address space (2^128 addresses) compared to that of its predecessor IPv4 (2^32 addresses). IPv6’s virtually unlimited address space has rendered tools/methods, developed for assessing the security and accessibility of IPv4 networks, obsolete. Specifically, methodologies for capturing Internet scanning traffic and probing state censorship architectures, developed in the context of IPv4’s limited address space, are ineffective when applied to IPv6 networks. A recent surge in threats incident on IPv6 networks coupled with increased adoption of the protocol mandates that we build IPv6-specific frameworks to characterize and mitigate these threats. In this dissertation, we outline the tools and methods we built – tailor made for IPv6’s expansive address space – to close this gap. In particular, we (1) build a distributed, asynchronous and stateful internet censorship measurement tool called ProtoScan and leverage open IPv6 DNS resolvers to feasibly conduct a global comparative study of internet censorship in IPv4 and IPv6 networks, and (2) introduce a novel method for building IPv6 network telescopes that utilizesactive regions of address space to attract IPv6 scanning traffic and deploy it in a production ISP network. Through these frameworks, we gather unprecedented insights into IPv6 scanning and censorship behaviors. Specifically, (1) we reveal significant coverage gaps in existing IPv6 censorship architectures, specifically highlighting substantial differences in DNS censorship between IPv4 and IPv6, revealing opportunities for new circumvention methods, and (2) collect ∼1 billion packets of unsolicited IPv6 scanning packets and identify novel IPv6-specific scanning techniques, uncover massive distributed IPv6 scanning campaigns and produce security postures to harden IPv6 networks against scanners. Taken together, this dissertation accomplishes two goals. (1) It provides a comprehensive picture of internet scanning, censorship and their intersection in the context of IPv6’s expansive address space as it continues to grow and (2) equip researchers and network operators with ready to use tools, methods and actionable findings to improve their IPv6 network’s security and accessibility.
Cyber Threats Internet Censorship Internet Scanning IPv6 Network Security

Details

Metrics

1 File views/ downloads
103 Record Views
Logo image