Structurally-Compliant IPv6 Extension-Header Command-and-Control: Signature Evasion and the Limits of Behavioral Detection

The continued deployment of IPv6 expands the network attack surface through its flexible Extension Header (EH) chain, whose sub-option semantics are frequently assumed rather than validated by intermediate nodes and monitoring software. We study both sides of this gap. Offensively, we present a proof-of-concept command-and-control (C2) channel that embeds an obfuscated payload in the PadN bytes of the IPv6 Destination Options EH and gates reception with a Flow-Label one-time selector driven by a pre-shared pseudorandom generator (a filter against blind, off-path injection—not a cryptographic authenticator, since the generator is a non-cryptographic Mersenne Twister and hence predictable); inserting the EH shifts the base-header Next Header field from 6 to 60, so that tcp port 443 Berkeley Packet Filter (BPF) rules and Next-Header Snort rules do not match, and a TLS-handshake masquerade evades deep-packet inspection (DPI) in our controlled testbed. We show, however, that a single stateless RFC 8200 check that rejects non-zero PadN content defeats this naive channel—motivating our central question: can the channel evade behavioral detection once an adversary shapes its PadN and Flow-Label statistics toward benign traffic? Defensively, we evaluate a rule baseline, three unsupervised detectors (Deep Autoencoder, One-Class SVM, Local Outlier Factor), and two supervised classifiers (Random Forest, RBF-SVM) over header-only features under a strict, leak-free split with thresholds fixed via Youden's J, following the evaluation guidance of Arp et al. Against the naive adversary, rule-based and supervised detection are near-perfect and trivial by construction: real MAWI benign traffic carries non-zero PadN in 0.0000% of 10^6 packets, so a one-rule matches the Random Forest. Against an adaptive adversary that abandons PadN and mimics benign Flow-Label and inter-arrival statistics, the aggregate supervised AUC-ROC falls from 0.92 to 0.49. Decomposing this, however, shows the fall is entirely a vanishing covert capacity: per-covert-packet detectability stays flat (≈ 0.92) across all mimicry levels, while covert capacity drops to zero. Stealth against aggregate detection is therefore bought only by spending capacity—an explicit trade-off, not per-packet evasion. These findings reframe behavioral detection of EH covert channels as an adversarial problem whose difficulty is set by the attacker's mimicry effort, not a solved classification task.

Authors

Institutions

Publication Details

Journal
Zenodo (CERN European Organization for Nuclear Research)
Published
2026-09-29
DOI
https://doi.org/10.5281/zenodo.23028965
Primary Topic
Network Security and Intrusion Detection
Type
preprint
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
preprint

Structurally-Compliant IPv6 Extension-Header Command-and-Control: Signature Evasion and the Limits of Behavioral Detection

Dang Truong Dinh
Zenodo (CERN European Organization for Nuclear Research)
Network Security and Intrusion Detection
preprint

Structurally-Compliant IPv6 Extension-Header Command-and-Control: Signature Evasion and the Limits of Behavioral Detection

Dang Truong Dinh
preprint en

Abstract

The continued deployment of IPv6 expands the network attack surface through its flexible Extension Header (EH) chain, whose sub-option semantics are frequently assumed rather than validated by intermediate nodes and monitoring software. We study both sides of this gap. Offensively, we present a proof-of-concept command-and-control (C2) channel that embeds an obfuscated payload in the PadN bytes of the IPv6 Destination Options EH and gates reception with a Flow-Label one-time selector driven by a pre-shared pseudorandom generator (a filter against blind, off-path injection—not a cryptographic authenticator, since the generator is a non-cryptographic Mersenne Twister and hence predictable); inserting the EH shifts the base-header Next Header field from 6 to 60, so that tcp port 443 Berkeley Packet Filter (BPF) rules and Next-Header Snort rules do not match, and a TLS-handshake masquerade evades deep-packet inspection (DPI) in our controlled testbed. We show, however, that a single stateless RFC 8200 check that rejects non-zero PadN content defeats this naive channel—motivating our central question: can the channel evade behavioral detection once an adversary shapes its PadN and Flow-Label statistics toward benign traffic? Defensively, we evaluate a rule baseline, three unsupervised detectors (Deep Autoencoder, One-Class SVM, Local Outlier Factor), and two supervised classifiers (Random Forest, RBF-SVM) over header-only features under a strict, leak-free split with thresholds fixed via Youden's J, following the evaluation guidance of Arp et al. Against the naive adversary, rule-based and supervised detection are near-perfect and trivial by construction: real MAWI benign traffic carries non-zero PadN in 0.0000% of 10^6 packets, so a one-rule matches the Random Forest. Against an adaptive adversary that abandons PadN and mimics benign Flow-Label and inter-arrival statistics, the aggregate supervised AUC-ROC falls from 0.92 to 0.49. Decomposing this, however, shows the fall is entirely a vanishing covert capacity: per-covert-packet detectability stays flat (≈ 0.92) across all mimicry levels, while covert capacity drops to zero. Stealth against aggregate detection is therefore bought only by spending capacity—an explicit trade-off, not per-packet evasion. These findings reframe behavioral detection of EH covert channels as an adversarial problem whose difficulty is set by the attacker's mimicry effort, not a solved classification task.

Zenodo (CERN European Organization for Nuclear Research)
Austin Peay State University (US)
Network Security and Intrusion Detection
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.