首页> 外文会议> >IPv6 Anomaly Traffic Monitoring with IPFIX
【24h】

IPv6 Anomaly Traffic Monitoring with IPFIX

机译:使用IPFIX的IPv6异常流量监控

获取原文

摘要

Though the IPv6 network is believed to be safe against security-violating exploits or attacks that were prevailed in IPv4, it is still expected that brand-new or mutational anomaly traffic will appear as IPv6 networks are being deployed. In this paper, among several anomaly traffic patterns we consider the possible IPv6 attacks that are utilizing ICMPv6, IPv6 extension headers, and IPv6-over-IPv4 tunneling. For IPv6 traffic measurement infrastructure, we employ IP Flow Information eXport (IPFIX) that has been standardized to generate the flow-level traffic measurement information. Thus, we present new IPFIX templates that have been extended to carry IPv6 anomaly traffic related with ICMPv6, IPv6 extension headers, and IPv6-over-IPv4 tunneling. Then, based on the extended IPFIX flow templates, we propose a simple IPv6 flow classification method that could be used for detecting IPv6 DoS attack, IPv6 covert channel exploiting destination option, and IPv6-over-IPv4 tunneling flows. From the experiments with our own IPFIX analyzer and the IPFIX flow-generating probe, we have shown that IPFIX is useful for monitoring normal IPv6 traffic as well as anomaly IPv6 traffic.
机译:尽管人们认为IPv6网络对于抵御IPv4中普遍存在的违反安全性的攻击或攻击是安全的,但仍有望在部署IPv6网络时出现全新的或突变的异常流量。在本文中,我们将在几种异常流量模式中考虑利用ICMPv6,IPv6扩展标头和IPv6-over-IPv4隧道传输的可能的IPv6攻击。对于IPv6流量测量基础架构,我们使用已标准化的IP流信息出口(IPFIX)来生成流级流量测量信息。因此,我们提出了新的IPFIX模板,这些模板已扩展为承载与ICMPv6,IPv6扩展标头和IPv6-over-IPv4隧道相关的IPv6异常流量。然后,基于扩展的IPFIX流模板,我们提出了一种简单的IPv6流分类方法,该方法可用于检测IPv6 DoS攻击,IPv6隐蔽信道利用目的地选项和IPv6-over-IPv4隧道流。通过使用我们自己的IPFIX分析器和IPFIX流生成探针进行的实验,我们已经证明IPFIX可用于监视正常的IPv6流量和异常的IPv6流量。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号