Structurally-Compliant IPv6 Extension-Header Command-and-Control: Signature Evasion and the Limits of Behavioral Detection
The continued deployment of IPv6 expands the network attack surface through its flexible Extension Header (EH) chain, whose sub-option semantics are frequently assumed rather than validated by intermediate nodes and monitoring software. We study both sides of this gap. Offensively, we present a proof-of-concept command-and-control (C2) channel that embeds an obfuscated payload in the PadN bytes of the IPv6 Destination Options EH and gates reception with a Flow-Label one-time selector driven by a pre-shared pseudorandom generator (a filter against blind, off-path injection—not a cryptographic authenticator, since the generator is a non-cryptographic Mersenne Twister and hence predictable); inserting the EH shifts the base-header Next Header field from 6 to 60, so that tcp port 443 Berkeley Packet Filter (BPF) rules and Next-Header Snort rules do not match, and a TLS-handshake masquerade evades deep-packet inspection (DPI) in our controlled testbed. We show, however, that a single stateless RFC 8200 check that rejects non-zero PadN content defeats this naive channel—motivating our central question: can the channel evade behavioral detection once an adversary shapes its PadN and Flow-Label statistics toward benign traffic? Defensively, we evaluate a rule baseline, three unsupervised detectors (Deep Autoencoder, One-Class SVM, Local Outlier Factor), and two supervised classifiers (Random Forest, RBF-SVM) over header-only features under a strict, leak-free split with thresholds fixed via Youden's J, following the evaluation guidance of Arp et al. Against the naive adversary, rule-based and supervised detection are near-perfect and trivial by construction: real MAWI benign traffic carries non-zero PadN in 0.0000% of 10^6 packets, so a one-rule matches the Random Forest. Against an adaptive adversary that abandons PadN and mimics benign Flow-Label and inter-arrival statistics, the aggregate supervised AUC-ROC falls from 0.92 to 0.49. Decomposing this, however, shows the fall is entirely a vanishing covert capacity: per-covert-packet detectability stays flat (≈ 0.92) across all mimicry levels, while covert capacity drops to zero. Stealth against aggregate detection is therefore bought only by spending capacity—an explicit trade-off, not per-packet evasion. These findings reframe behavioral detection of EH covert channels as an adversarial problem whose difficulty is set by the attacker's mimicry effort, not a solved classification task.
Authors
- Dang Truong Dinh (ORCID: https://orcid.org/0009-0005-9459-6486)
Institutions
- Austin Peay State University (US)
Publication Details
- Journal
- Zenodo (CERN European Organization for Nuclear Research)
- Published
- 2026-09-29
- DOI
- https://doi.org/10.5281/zenodo.23029268
- Primary Topic
- Network Security and Intrusion Detection
- Type
- preprint