首页> 外文期刊>Computers & Security >Methodology for the identification of potential security issues of different IPv6 transition technologies: Threat analysis of DNS64 and stateful NAT64
【24h】

Methodology for the identification of potential security issues of different IPv6 transition technologies: Threat analysis of DNS64 and stateful NAT64

机译:识别不同IPv6过渡技术的潜在安全问题的方法:DNS64和有状态NAT64的威胁分析

获取原文
获取原文并翻译 | 示例

摘要

We are faced with the transition from IPv4 to IPv6, which will last for several years or possibly decades. There are different IPv6 transition technologies, which enable the communication between hosts using the two incompatible versions of the Internet Protocol in various scenarios, but they also involve additional security issues. In this paper, we develop a methodology for the identification of potential security issues of different IPv6 transition technologies and their implementations based on the STRIDE approach and its application to IPv6 transition technologies. Our methodology includes the application of the STRIDE approach at two levels: the level of the individual IPv6 transition technologies and the level of their selected implementations. We demonstrate the operation and viability of our methodology by the detailed threat analysis of the DNS64 technology, and we prove the necessity of the implementation level analysis with several examples. We also include the most interesting highlights of the security analysis of the stateful NAT64 IPv6 transition technology. We also make a survey of the published vulnerabilities of DNS64 and NAT64 in different research papers and show the effectiveness of our systematic method by uncovering the threats of DNS64 and NAT64. Finally, we point out the need for the in-depth security analysis of the DNS64 technology and its most important implementations. (C) 2018 Elsevier Ltd. All rights reserved.
机译:我们面临着从IPv4到IPv6的过渡,过渡将持续数年甚至数十年。 IPv6过渡技术不同,可以在各种情况下使用Internet协议的两个不兼容版本在主机之间进行通信,但是它们还涉及其他安全问题。在本文中,我们基于STRIDE方法及其在IPv6过渡技术中的应用,开发了一种用于识别不同IPv6过渡技术及其实现的潜在安全问题的方法。我们的方法包括在两个级别上应用STRIDE方法:单个IPv6过渡技术的级别和其选定实现的级别。我们通过对DNS64技术的详细威胁分析来证明我们的方法的操作性和可行性,并通过几个示例来证明实施级别分析的必要性。我们还提供了有状态NAT64 IPv6过渡技术的安全性分析中最有趣的亮点。我们还对不同研究论文中已发布的DNS64和NAT64漏洞进行了调查,并通过发现DNS64和NAT64的威胁来证明我们的系统方法的有效性。最后,我们指出有必要对DNS64技术及其最重要的实现进行深入的安全分析。 (C)2018 Elsevier Ltd.保留所有权利。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号