Your Router is My Prober: Measuring IPv6 Networks via ICMP Rate Limiting Side Channels
Long Pan, Jiahai Yang, Lin He, Zhiliang Wang, Leyao Nie, Guanglei, Song, Yaozhong Liu

TL;DR
This paper introduces iVantage, a novel technique leveraging ICMP rate limiting side channels to measure IPv6 network deployment and reachability from a single vantage point, enabling large-scale, remote network analysis.
Contribution
We propose iVantage, a new method exploiting ICMP rate limiting side channels to perform large-scale IPv6 network measurements without multiple vantage points or target control.
Findings
Measured ~50% of IPv6 ASes for ISAV vulnerabilities.
Found ~79% of IPv6 ASes vulnerable to spoofing.
Achieved over 80% accuracy in reachability measurements.
Abstract
Active Internet measurements face challenges when some measurements require many remote vantage points. In this paper, we propose a novel technique for measuring remote IPv6 networks via side channels in ICMP rate limiting, a required function for IPv6 nodes to limit the rate at which ICMP error messages are generated. This technique, iVantage, can to some extent use 1.1M remote routers distributed in 9.5k autonomous systems and 182 countries as our "vantage points". We apply iVantage to two different, but both challenging measurement tasks: 1) measuring the deployment of inbound source address validation (ISAV) and 2) measuring reachability between arbitrary Internet nodes. We accomplish these two tasks from only one local vantage point without controlling the targets or relying on other services within the target networks. Our large-scale ISAV measurements cover ~50% of all IPv6…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Code & Models
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsIPv6, Mobility, Handover, Networks, Security · Network Security and Intrusion Detection · Transplantation: Methods and Outcomes
