Kirin: Hitting the Internet with Millions of Distributed IPv6 Announcements
Lars Prehn, Pawel Foremski, Oliver Gasser

TL;DR
This paper introduces Kirin, a sophisticated IPv6 prefix de-aggregation attack that leverages millions of distributed BGP announcements to overwhelm border routers, highlighting new security vulnerabilities in the expanding IPv6 Internet infrastructure.
Contribution
Kirin is a novel, highly distributed attack method that bypasses traditional defenses by sourcing and distributing millions of IPv6 routes across multiple IXPs, demonstrating a new threat to Internet routing security.
Findings
Kirin can inject millions of IPv6 routes into target ASes.
The attack bypasses traditional route-flooding defenses.
Feasibility confirmed through real-world experiments and data analysis.
Abstract
The Internet is a critical resource in the day-to-day life of billions of users. To support the growing number of users and their increasing demands, operators have to continuously scale their network footprint -- e.g., by joining Internet Exchange Points -- and adopt relevant technologies -- such as IPv6. IPv6, however, has a vastly larger address space compared to its predecessor, which allows for new kinds of attacks on the Internet routing infrastructure. In this paper, we revisit prefix de-aggregation attacks in the light of these two changes and introduce Kirin -- an advanced BGP prefix de-aggregation attack that sources millions of IPv6 routes and distributes them via thousands of sessions across various IXPs to overflow the memory of border routers within thousands of remote ASes. Kirin's highly distributed nature allows it to bypass traditional route-flooding defense…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsSoftware-Defined Networks and 5G · Internet Traffic Analysis and Secure E-voting · Network Packet Processing and Optimization
