【24h】

Flow-Based Detection of IPv6-specific Network Layer Attacks

机译:基于流的IPv6特定网络层攻击检测

获取原文

摘要

With a vastly different header format, IPv6 introduces new vulnerabilities not possible in IPv4, potentially requiring new detection algorithms. While many attacks specific to IPv6 have proven to be possible and are described in the literature, no detection solutions for these attacks have been proposed. In this study we identify and characterise IPv6-specific attacks that can be detected using flow monitoring. By constructing flow-based signatures, detection can be performed using available technologies such as NetFlow and IPFIX. To validate our approach, we implemented these signatures in a prototype, monitoring two production networks and injecting attacks into the production traffic.
机译:具有众多不同的报头格式,IPv6在IPv4中引入了无法实现的新漏洞,可能需要新的检测算法。虽然特定于IPv6的攻击已经证明是可能的并且在文献中描述,但没有提出这些攻击的检测解决方案。在本研究中,我们识别和表征可以使用流量监控检测的IPv6特定攻击。通过构建基于流的签名,可以使用诸如NetFlow和IPFIX的可用技术来执行检测。为了验证我们的方法,我们在原型中实施了这些签名,监控了两个生产网络并注入了生产流量的攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号