DEH-DoSv6: A defendable security model against IPv6 extension headers denial of service attack

Marlon A. Naagas, Alvin R. Malicdem, Thelma D. Palaoag


With the rapid depletion of IPv4 protocol in these recent years, the IETF introduced IPv6 as a solution to address the exhaustion, however, as a new protocol exists, new characteristics have been introduced and new threats have been discovered. Extension Headers are the new characteristics of IPv6 that have an emerging and re-emerging security threats that is needed to be taken into consideration during the full migration to the IPv6 network. This study revealed that up to this moment, the popular vendors are still vulnerable and doesn’t have any default protection to deal with extension headers’ Denial of Service Attack (DoS). Also, this study leads to the development of new security model which creates a new solution to address the emerging threats of IPv6 extension headers’ Denial of Service Attack. Moreover, the results of this study show that our proposed security model is more effective in terms of neutralizing the unwanted traffic causing evasion attack by filtering, rate-limiting and discarding the malformed packets of prohibited extension headers’ payload versus the traditional router protection.


IPv6 denial of service; IPv6 emerging threat; IPv6 evasion technique; IPv6 extension headers; IPv6 security model

Full Text:




  • There are currently no refbacks.

Bulletin of EEI Stats