Off-Path Network Traffic Manipulation via Revitalized ICMP Redirect (2022) [pdf]
usenix.org
usenix.org
> As a result, our attacks can be easily extended to IPv6 net- works to manipulate a victim originator’s network traffic.
So if the host generated IDs on such a basis, maintaining a tuple indexed set of IDs (with some time window), then before any higher level validation is performed , a simple check that the ID in the embedded packet is in the correct range for the SRC/DST/PROTO combo would allow such packets to be discarded.
An additional bit could be maintained to indicate that an attack was detected, just in case some device tries to scan through the 16 bit range. Hence catching that on a per target basis.
This would allow the on local LAN case to be protected against, and would also serve to protect against the remote case, but that should really be handled by the edge router.
e.g. my home router currently shows a number of filtered inbound redirects:
190 deny icmp any any redirect (542 matches)
For IPv6 one could probably perform a similar scheme, but using the flow-id field.