期刊文献+

IPv6路由报头安全漏洞的保护方案 被引量:1

Protection scheme for security holes of IPv6 routing header
下载PDF
导出
摘要 目前的网络是基于IPv4的,但是IPv4的种种局限性限制了网络的持续高速发展。这时候IPv6被开发出来作为IPv4的替换品I。Pv6有很多的优势,例如巨大的地址空间、自动配置机制、简化的报头结构、内置IPSec、扩展报头以及对流标签的支持等。但是,IPv6中的安全漏洞也陆续被发现。路由报头是一种扩展报头,可以让一个IPv6源地址经过若干中间节点之后到达目的地址。路由报头可以使攻击者绕过安全系统的访问控制检查,访问到受保护的内部主机。介绍了一种解决IPv6路由报头安全漏洞的方案。 Current intemet is based on IPv4 protocol, but the limitation of IPv4 put obstacle to the development of intemet. IPv6 is carried out as an alternative of IPv4, IPv6 has many features such as: 128 bit address, auto-configuration mechanism, simple header format, using IPSec, extend header, support of flow label. Meanwhile security holes of IPv6 are fined. Routing header is a kind of extend header, to let the source list one or more intermediate nodes to be visited on the way to the destination. Routing header make it possible for attackers to detour the security system, and visit the internal hosts, this causes new security problems. The scheme introduced in this article solves the security holes caused by using routing header.
出处 《计算机工程与设计》 CSCD 北大核心 2008年第12期3055-3057,共3页 Computer Engineering and Design
关键词 路由报头 网络安全 包过滤 过滤规则 IPV6防火墙 routing header network security packet filtering filtering rules IPv6 firewall
  • 相关文献

参考文献8

二级参考文献96

  • 1Postel J.Internet Protocol.IETF RFC 791,Sep.1981
  • 2Carpenter B,Moore K.Connection of IPv6 Domains via IPv4 Clouds.IETF RFC 3056,Feb.2001
  • 3Huitema C.Teredo:Tunneling IPv6 over UDP through NATs.Internet-Draft draft-huitema-v6ops-teredo-05,Apr.2005
  • 4Davies E,Krishnan S.IPv6 Transition/Co-existence Security Considerations.Internet-Draft draft-savola-v6ops-security-overview-03,Oct.2004
  • 5Savola P,Patel C.Security Considerations for 6to4.IETF RFC 3964,Dec.2004
  • 6Srisuresh P,Tsirtsis G.DNS extensions to Network Address Translators (DNS-ALG).IETF RFC 2694,Sep.1999
  • 7Okazaki S,Desai A.NAT-PT Security Considerations.Internet-Draft draft-okazaki-v6ops-natpt-security-00,Jun.2003
  • 8Park S D.Scalable mNAT-PT Solution.Internet-Draft draft-park-scalable-multi-natpt-0,May 2003
  • 9Eastlake D.Domain Name Security Extensions.IETF RFC 2535,Mar.1999
  • 10Durand A.Issues with NAT-PT DNS ALG in RFC2766.Internet-Draft draft-durand-v6ops-natpt-dns-alg-issues-00,Jan.2003

共引文献45

同被引文献13

引证文献1

二级引证文献3

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部