SLIDE 16 Methodology Too-Big Trick
Too-Big Trick
Too-Big Trick Our prober sends ICMP6 echos and fake PTBs Inducing remote IPv6 router to originate fragmented packets
Prober
I C M P 6 E c h
e q 1 3 B , S e q = 1 I C M P 6 E c h
e q 1 3 B , S e q = I C M P E c h
e s p 1 3 B I C M P 6 T
i g F r a g I D = x , O f f s e t = F r a g I D = x , O f f s e t = 1 2 3 2 I C M P 6 E c h
e q 1 3 B , S e q = 2 F r a g I D = x + 1 , O f f s e t = F r a g I D = x + 1 , O f f s e t = 1 2 3 2
IPv6 Interface
Fragment identifier is (frequently) monotonically increasing and resets to 0 on (most) IPv6 stacks, including routers
(NPS/CAIDA) IPv6 Router Uptime PAM 2015 11 / 28