IPv6 - The devil you don't know...

This is the first in a four-part series of articles on IPv6 security issues.

“Better the devil you know than the devil you don't”. No matter how bad something is, knowing about it is half the battle won. So when something new comes along, like IPv6, its very newness is an issue.

Where IPv6 works the same as IPv4, our knowledge translates quite directly. But there are fundamental differences; it will take time and operational experience to understand their subtleties.

The basic problem is that you don't yet know what those differences are. Nor do your suppliers, staff, or service providers. Even where differences are known about, there is no feel yet for how they will play out operationally. Ignorance means risk that cannot be managed, but equally importantly for IPv6, opportunity that cannot be grasped.

The fact that IPv6 has more addresses seems simple enough, but it has game- changing effects. IPv4 address planning always starts with “how many hosts?” In IPv6 we work with subnets and can forget the addresses. This is a hugely liberating thing, but it takes real effort to get over the assumption, born of many years of IPv4 address scarcity, that we must conserve addresses.

Another game-changer is that there is no longer any need for NAT (network address translation). NAT too was born of address scarcity, which with IPv6 is a thing of the past. NAT does stateful packet inspection as a side-effect, but that can be had independently of NAT – global addressability is not the same as global reachability! What are the risks and opportunities where end-to-end transparency is ubiquitous?
If we model our IPv6 networks on our IPv4 networks we may end up with something that works, but we will be tying ourselves to old topologies and blocking our ability to innovate.

Another new aspect of IPv6 is stateless address autoconfiguration (SLAAC). In the presence of an IPv6 router, an IPv6 interface will give itself a globally-routable IPv6 address, completely automatically. It builds the address from a prefix supplied by the router and locally held information – by default, the hardware identifier of the interface.

This means that the hardware identifier of the interface (typically a MAC address) is visible to any host that receives a packet from you. And as long as you don't change the hardware, the last part of your address will stay the same, even as you move from network to network.

Whether this is a security issue is debatable. My own opinion is that information about host network hardware is rarely of significant advantage to an attacker; and in any case only if the host is reachable, which most enterprise hosts will not be. From a privacy point of view, however, an autoconfigured address is a sort of super-cookie. It allows a particular host to be tracked wherever it goes.

IPv6 allows you to avoid this by using “privacy addresses”. With privacy addressing, a host builds its address using a random sequence of bits instead of a hardware identifier. It changes the random sequence every so often, making it very hard to track the host.

Autoconfiguration takes place without any policy hooks and without any logging. For these and other reasons (including privacy concerns), DHCP is likely to retain a place in most enterprises, either as an adjunct to or instead of SLAAC.
Stateless address autoconfiguration is a good example of something new in IPv6 that needs to be thought about and considered as you deploy IPv6.

©Copyright 2011 Karl Auer

About the author: Karl is technical manager atIPv6Now a company specialising in helping organisations get into and get the most out of IPv6.

Tags: Autoconfiguration, ipv4, IPv6, IPv6 security, NAT (network address translation), online news, security

Comments

1

kumarvikram

Sun 04/09/2011 - 03:20

project olline

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the CSO comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
CSO Corporate Partners
  • FirEye
  • Clear Swift
  • Trend Micro
  • Sophos
  • NetIQ
rhs_login_lockGet exclusive access to CSO, invitation only events, reports & analysis.
CSO Directory

AVG Internet Security 2011 Business Edition

Ultimate protection for your small or medium-sized business

Security Awareness Tip
Clearswift tips: Guidelines for introducing and policing an effective IT Policy

1. Make it clear that the policy is not about playing ‘Big Brother’ but to ensure the security of employees, company information and data and to safeguard the company’s reputation.
2. Invest time to get buy-in from managers and their teams.
3. Convey the message of flexibility – with regard to social media, it is not about blocking staff usage but working in everyone’s interests to ensure that threats are contained.
4. Introduce a regular company-wide training programme that everyone attends at regular intervals throughout the year, not merely as part of an induction programme.
5. Within the training programme make sure that there are specific examples to demonstrate each rule or regulation, and that there is a clear explanation of the dangers of casual or careless talk on social networking sites. Again use examples, employees need to understand the consequences of raising a throwaway comment that has negative connotations for the business, as much as they need to be aware of dangers of making a more direct but ill-considered attack on a competitor, regulator or even a fellow colleague. They need to be clearly advised on any impact on the company and/or legal action or inquires that may be raised as a result.
6. Alert employees to any changes in policy through regular clear communication.
7. Reinforce the operational policy guidelines regularly, cover everything from blogging to Facebook, LinkedIn and Twitter.
8. Ensure that the rules are fair and that they apply throughout the business.
9. Enforce the rules – if there is a deliberate or malicious contravening, disciplinary action needs to be taken. A policy isn’t worth having if it is seen to be lax and unenforced.
10. Review the policy regularly to ensure you keep up to date with new systems and technology.

Phil Vasic is Regional Director, APAC, at Clearswift, the software security company www.clearswift.com
Security ABC Guides

7 Ways to Protect Your Business Printers

Can a hacker burn down your business by remotely setting one of your printers on fire? Researchers at Columbia University have recently proposed such a scenario, although HP quickly denied that it's possible. However, even if your printers can't be used as remote firestarters, there are many risks involved in networking a printer.