SlideShare a Scribd company logo
DDoSChallenges
InIPv6environment
2
I’m Pavel Odintsov, the author of open source DDoS detection tool,
FastNetMon: https://github.com/pavel-odintsov/fastnetmon
Ways to contact me:
● linkedin.com/in/podintsov
● github.com/pavel-odintsov
● twitter.com/odintsov_pavel
● IRC, FreeNode, pavel_odintsov
● pavel.odintsov@gmail.com
3
Image from https://thirdinternet.com/ip-packet-syntax/
4
Image from https://networkel.com/ipv6-overview-communication-types/
5
● Protocol flood (UDP, ICMP, GRE, TCP). Just keep the protocol
field static.
● Fragmentation attack (just set fragment flags: DF, MF and
Fragment Offset).
● Spoofing attack type (just randomize source IP)
● Options flood (just add more options)
● Empty packet flood (set length to 0)
● TTL expiration attack (very low or even zero TTL)
● ToS flood, just set random values here
6
Image from https://www.lifewire.com/tcp-headers-and-udp-headers-explained-817970
7
● Source port flood (including zero port)
● Destination port flood (including zero port)
● TCP Sequence flood
● TCP Ack field flood
● TCP Flag flood (TCP, ACK)
● TCP Window size flood (including 0)
8
● TCP flag flood (i.e. SYN, ACK flood)
● UDP flood
● GRE flood
● UDP amplification (DNS, NTP, SSDP, SNMP)
● Fragmentation attack
● Spoofed source attacks
9
Data from https://www.google.com/intl/en/ipv6/statistics.html
10
Data from https://www.akamai.com/uk/en/resources/our-thinking/state-of-the-internet-report
11
Data from https://www.akamai.com/uk/en/resources/our-thinking/state-of-the-internet-report
⬥ Telemetry about IPv6
⬥ BGP for IPv6
⬥ Blackhole RFC 7999 for IPv6
⬥ Traffic engineering for IPv6
12
⬥ Netflow v5, no fields for IPv6 addresses
⬥ No ways to send Netflow, IPFIX, sFlow v5 to IPv6 only collector
13
⬥ Netflow v9, IPFIX, sFlow v5
14
⬥ MPReach instead of old good NLRI for IPv4
⬥ BGP Daemon implementation
15
16
⬥ Only /128 support
⬥ No support
⬥ Non RFC community number, please use
RFC7999
17
⬥ Diversion can be implemented on customer
basis
⬥ Ability to localise customer for RTBH purposes
⬥ Anycast is affordable
18
19
20
⬥ Complete IPv6 support for mirror, Netflow and
IPFIX modes
⬥ Added logic to ban / unban IPv6 hosts manually
via API and fastnetmon_api_client
⬥ Added logic to announce / withdraw announces
about IPv6 hosts
21
22
⬥ wget
https://raw.githubusercontent.com/pavel-odints
ov/fastnetmon/master/src/fastnetmon_install.pl
-Ofastnetmon_install.pl
⬥ sudo perl fastnetmon_install.pl
ANY QUESTIONS?
You can find me at:
⬥ @odintsov_pavel
⬥ pavel.odintsov@gmail.com
⬥ linkedin.com/in/podintsov
23

More Related Content

PPTX
FastNetMon Advanced DDoS detection tool
PDF
Using MikroTik routers for BGP transit and IX points
PDF
DDoS Defense Mechanisms for IXP Infrastructures
PPTX
BGP FlowSpec experience and future developments
PDF
Blackholing from a_providers_perspektive_theo_voss
PPTX
DeiC DDoS Prevention System - DDPS
PDF
Detecting and mitigating DDoS ZenDesk by Vicente De Luca
PDF
Jon Nield FastNetMon
FastNetMon Advanced DDoS detection tool
Using MikroTik routers for BGP transit and IX points
DDoS Defense Mechanisms for IXP Infrastructures
BGP FlowSpec experience and future developments
Blackholing from a_providers_perspektive_theo_voss
DeiC DDoS Prevention System - DDPS
Detecting and mitigating DDoS ZenDesk by Vicente De Luca
Jon Nield FastNetMon

What's hot (20)

PDF
GoBGP : yet another OSS BGPd
PDF
FastNetMon - ENOG9 speech about DDoS mitigation
PDF
Ripe71 FastNetMon open source DoS / DDoS mitigation
PDF
Protect your edge BGP security made simple
PDF
Implementing BGP Flowspec at IP transit network
PDF
Distributed Denial of Service Attack - Detection And Mitigation
PDF
DDoS Mitigation Tools and Techniques
PDF
Nanog66 vicente de luca fast netmon
PDF
Keeping your rack cool
PPT
PDF
Ultra fast DDoS Detection with FastNetMon at Coloclue (AS 8283)
PDF
FastNetMonを試してみた
PDF
WebRTC meetup barcelona 2017
PDF
Preventing Traffic with Spoofed Source IP address
PDF
VPN Overview and IPsec Intro
PDF
Make the internet safe with DNS Firewall
PDF
Introduction to OverTheBox
PPTX
Recon with Nmap
PDF
Let's talk about routing security, Anurag Bhatia, Hurricane Electric
GoBGP : yet another OSS BGPd
FastNetMon - ENOG9 speech about DDoS mitigation
Ripe71 FastNetMon open source DoS / DDoS mitigation
Protect your edge BGP security made simple
Implementing BGP Flowspec at IP transit network
Distributed Denial of Service Attack - Detection And Mitigation
DDoS Mitigation Tools and Techniques
Nanog66 vicente de luca fast netmon
Keeping your rack cool
Ultra fast DDoS Detection with FastNetMon at Coloclue (AS 8283)
FastNetMonを試してみた
WebRTC meetup barcelona 2017
Preventing Traffic with Spoofed Source IP address
VPN Overview and IPsec Intro
Make the internet safe with DNS Firewall
Introduction to OverTheBox
Recon with Nmap
Let's talk about routing security, Anurag Bhatia, Hurricane Electric
Ad

Similar to DDoS Challenges in IPv6 environment (20)

PDF
IPv6 Security Overview by QS Tahmeed, APNIC RCT
PDF
HKNOG 1.0 - DDoS attacks in an IPv6 World
PDF
Network telemetry for DDoS detection presentation
PDF
Detection of ICMPv6-based DDoS attacks using anomaly based intrusion detectio...
PDF
IPv6 Fundamentals & Securities
PPTX
APNIC Hackathon IPv4 & IPv6 security & threat comparisons
PPTX
APNIC Hackathon IPv4 & IPv6 security & threat comparisons
PPT
IPV6 Under the Hood
PPT
MAGPI: Advanced Services: IPv6, Multicast, DNSSEC
PPT
ASCC Network Experience in IPv6
PDF
Is IPv6 Security Still an Afterthought?
PDF
PLNOG 5: Merike Kaeo - Something Old Is New Again
PDF
Improved Applications with IPv6: an overview
PDF
Ipv6 Security with Mikrotik RouterOS by Wardner Maia
PPT
Understanding i pv6 2
PDF
Guide to TCP/IP: IPv6 and IPv4 5th Edition
PPTX
Packet Analysis - Course Technology Computing Conference
PDF
Utilizing Data Mining Approches in the Detection of Intrusion in IPv6 Network...
PPTX
BGP Flowspec (RFC5575) Case study and Discussion
PDF
The Internet - By the numbers, presented at npNOG 11
IPv6 Security Overview by QS Tahmeed, APNIC RCT
HKNOG 1.0 - DDoS attacks in an IPv6 World
Network telemetry for DDoS detection presentation
Detection of ICMPv6-based DDoS attacks using anomaly based intrusion detectio...
IPv6 Fundamentals & Securities
APNIC Hackathon IPv4 & IPv6 security & threat comparisons
APNIC Hackathon IPv4 & IPv6 security & threat comparisons
IPV6 Under the Hood
MAGPI: Advanced Services: IPv6, Multicast, DNSSEC
ASCC Network Experience in IPv6
Is IPv6 Security Still an Afterthought?
PLNOG 5: Merike Kaeo - Something Old Is New Again
Improved Applications with IPv6: an overview
Ipv6 Security with Mikrotik RouterOS by Wardner Maia
Understanding i pv6 2
Guide to TCP/IP: IPv6 and IPv4 5th Edition
Packet Analysis - Course Technology Computing Conference
Utilizing Data Mining Approches in the Detection of Intrusion in IPv6 Network...
BGP Flowspec (RFC5575) Case study and Discussion
The Internet - By the numbers, presented at npNOG 11
Ad

More from Pavel Odintsov (11)

PDF
BGP Flow Spec HKNOG 13
PDF
VietTel AntiDDoS Volume Based
PPTX
Flowspec contre les attaques DDoS : l'expérience danoise
PDF
Detectando DDoS e intrusiones con RouterOS
PDF
Lekker weer nlnog_nlnog_ddos_fl
PDF
Lekker weer nlnog_how_to_avoid_buying_expensive_routers
PDF
Janog 39: speech about FastNetMon by Yutaka Ishizaki
PDF
SIG-NOC Tools Survey
PDF
DDoS detection at small ISP by Wardner Maia
PDF
03 estrategia-ddos
PDF
Containers in real world презентация
BGP Flow Spec HKNOG 13
VietTel AntiDDoS Volume Based
Flowspec contre les attaques DDoS : l'expérience danoise
Detectando DDoS e intrusiones con RouterOS
Lekker weer nlnog_nlnog_ddos_fl
Lekker weer nlnog_how_to_avoid_buying_expensive_routers
Janog 39: speech about FastNetMon by Yutaka Ishizaki
SIG-NOC Tools Survey
DDoS detection at small ISP by Wardner Maia
03 estrategia-ddos
Containers in real world презентация

Recently uploaded (20)

PPTX
Cloud computing and distributed systems.
DOCX
The AUB Centre for AI in Media Proposal.docx
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PPTX
Big Data Technologies - Introduction.pptx
PDF
Network Security Unit 5.pdf for BCA BBA.
PDF
Spectral efficient network and resource selection model in 5G networks
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PPTX
MYSQL Presentation for SQL database connectivity
PDF
Encapsulation theory and applications.pdf
PDF
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PDF
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PDF
Electronic commerce courselecture one. Pdf
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PPTX
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
PDF
Encapsulation_ Review paper, used for researhc scholars
PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
PPTX
Understanding_Digital_Forensics_Presentation.pptx
PPTX
ACSFv1EN-58255 AWS Academy Cloud Security Foundations.pptx
Cloud computing and distributed systems.
The AUB Centre for AI in Media Proposal.docx
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
Big Data Technologies - Introduction.pptx
Network Security Unit 5.pdf for BCA BBA.
Spectral efficient network and resource selection model in 5G networks
The Rise and Fall of 3GPP – Time for a Sabbatical?
MYSQL Presentation for SQL database connectivity
Encapsulation theory and applications.pdf
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
Digital-Transformation-Roadmap-for-Companies.pptx
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
“AI and Expert System Decision Support & Business Intelligence Systems”
Electronic commerce courselecture one. Pdf
Mobile App Security Testing_ A Comprehensive Guide.pdf
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
Encapsulation_ Review paper, used for researhc scholars
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
Understanding_Digital_Forensics_Presentation.pptx
ACSFv1EN-58255 AWS Academy Cloud Security Foundations.pptx

DDoS Challenges in IPv6 environment