首页> 外文OA文献 >The Unexplored Impact of IPv6 on Intrusion Detection Systems
【2h】

The Unexplored Impact of IPv6 on Intrusion Detection Systems

机译:IPv6对入侵检测系统的未开发影响

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

With DoD networks steadily adopting and transitioning to the next generation Internet Protocol, IPv6, careful considerationmust be given to IPv6-specific implications on network protection. While Network Intrusion Detection Systems (NIDS) assistin protecting current IPv4 DoD networks, NIDS performance in operational DoD IPv6 environments is largely unknown. As astep toward more rigorous NIDS evaluation, we investigate the extent to which known IPv4 attacks are able to evade detectionwhen converted to equivalent IPv6 attacks. Utilizing 13 general attack classes, we test the IPv6 readiness of two popular opensource NIDSs: SNORT and BRO. Attacks in each class are evaluated in a virtual test bed that models both “native” and“transitional” networks. In the native IPv6 environment, we achieve a 95% detection rate for SNORT as compared to 8% withBRO. In addition, we discover a bug in SNORT where a carefully crafted IPv6 packet causes the NIDS to fail open, allowingfull circumvention. Our findings suggest that, with respect to IPv6, both NIDS signatures and NIDS software requireadditional testing and evaluation to be operationally ready.
机译:随着DoD网络稳步采用并过渡到下一代Internet协议IPv6,必须仔细考虑IPv6特定的网络保护含义。尽管网络入侵检测系统(NIDS)可以帮助保护当前的IPv4 DoD网络,但在运行中的DoD IPv6环境中NIDS的性能仍然未知。为了朝着更严格的NIDS评估迈进,我们调查了已知的IPv4攻击在转换为等效的IPv6攻击时能够逃避检测的程度。利用13种通用攻击类别,我们测试了两种流行的开源NIDS:SNORT和BRO的IPv6准备情况。在模拟“本地”和“过渡”网络的虚拟测试台中评估每个类别的攻击。在原生IPv6环境中,SNORT的检测率达到95%,而使用BRO的检测率为8%。此外,我们在SNORT中发现了一个错误,该错误中精心制作的IPv6数据包导致NIDS无法打开,从而可以完全规避。我们的发现表明,就IPv6而言,NIDS签名和NIDS软件都需要进行额外的测试和评估,才能投入使用。

著录项

  • 作者

    Gehrke Keith A.;

  • 作者单位
  • 年度 2012
  • 总页数
  • 原文格式 PDF
  • 正文语种
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号