Related Experiment Video
Updated: Dec 21, 2025

Automated Deployment of an Internet Protocol Telephony Service on Unmanned Aerial Vehicles Using Network Functions Virtualization
Published on: November 26, 2019
Mechanism to prevent the abuse of IPv6 fragmentation in OpenFlow networks
Ayman Al-Ani1, Mohammed Anbar1, Shams A Laghari1
1National Advanced IPv6 Center, Universiti Sains Malaysia, Gelugor, Penang, Malaysia.
Abstract:
OpenFlow makes a network highly flexible and fast-evolving by separating control and data planes. The control plane thus becomes responsive to changes in topology and load balancing requirements. OpenFlow also offers a new approach to handle security threats accurately and responsively. Therefore, it is used as an innovative firewall that acts as a first-hop security to protect networks against malicious users. However, the firewall provided by OpenFlow suffers from Internet protocol version 6 (IPv6) fragmentation, which can be used to bypass the OpenFlow firewall. The OpenFlow firewall cannot identify the message payload unless the switch implements IPv6 fragment reassembly. This study tests the IPv6 fragmented packets that can evade the OpenFlow firewall, and proposes a new mechanism to guard against attacks carried out by malicious users to exploit IPv6 fragmentation loophole in OpenFlow networks. The proposed mechanism is evaluated in a simulated environment by using six scenarios, and results exhibit that the proposed mechanism effectively fixes the loophole and successfully prevents the abuse of IPv6 fragmentation in OpenFlow networks.
Related Concept Videos
IP3/DAG Signaling Pathway
Habitat Fragmentation
Long-patch Base Excision Repair
Rapidly Varying Flow
Uniform Depth Channel Flow: Problem Solving
Fast Decoupled and DC Powerflow

