Integration of Firewall and IDS on Securing Mobile IPv6

S. Praptodiyono, Moh. Jauhari, R. Fahrizal, I. Hasbullah, A. Osman, Shafiq Ul Rehman
{"title":"Integration of Firewall and IDS on Securing Mobile IPv6","authors":"S. Praptodiyono, Moh. Jauhari, R. Fahrizal, I. Hasbullah, A. Osman, Shafiq Ul Rehman","doi":"10.1109/ICIEE49813.2020.9277354","DOIUrl":null,"url":null,"abstract":"The number of Mobile device users in the word has evolved rapidly. Many internet users currently want to connect the internet for all utilities automatically. One of the technologies in the IPv6 network, which supports data access from moving users, is IPv6 Mobile protocol. In its mobility, the users on a range of networks can move the range to another network. High demand for this technology will interest to a hacker or a cracker to carry out an attack. One of them is a DoS attack that compromises a target to denial its services. A firewall is usually used to protect networks from external attacks. However, since the firewall based on the attacker database, the unknown may not be detected. In order to address the obstacle, a detection tool could be used. In this research, IDS as an intrusion detection tool was integrated with a firewall to be implemented in IPv6 Mobile to stop the DoS attack. The results of some experiments showed that the integration system could block the attack at 0.9 s in Correspondent Node and 1.2 s in Home Agent. The blocked attack can decrease the network throughput up to 27.44% when a Mobile Node in Home Agent, 28,87% when the Mobile Node in a Foreign Network. The final result of the blocked attack is reducing the average CPU utilization up to 30.99%.","PeriodicalId":127106,"journal":{"name":"2020 2nd International Conference on Industrial Electrical and Electronics (ICIEE)","volume":null,"pages":null},"PeriodicalIF":0.0000,"publicationDate":"2020-10-20","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2020 2nd International Conference on Industrial Electrical and Electronics (ICIEE)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICIEE49813.2020.9277354","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

The number of Mobile device users in the word has evolved rapidly. Many internet users currently want to connect the internet for all utilities automatically. One of the technologies in the IPv6 network, which supports data access from moving users, is IPv6 Mobile protocol. In its mobility, the users on a range of networks can move the range to another network. High demand for this technology will interest to a hacker or a cracker to carry out an attack. One of them is a DoS attack that compromises a target to denial its services. A firewall is usually used to protect networks from external attacks. However, since the firewall based on the attacker database, the unknown may not be detected. In order to address the obstacle, a detection tool could be used. In this research, IDS as an intrusion detection tool was integrated with a firewall to be implemented in IPv6 Mobile to stop the DoS attack. The results of some experiments showed that the integration system could block the attack at 0.9 s in Correspondent Node and 1.2 s in Home Agent. The blocked attack can decrease the network throughput up to 27.44% when a Mobile Node in Home Agent, 28,87% when the Mobile Node in a Foreign Network. The final result of the blocked attack is reducing the average CPU utilization up to 30.99%.
防火墙与入侵检测集成在移动IPv6安全中的应用
世界上移动设备用户的数量发展迅速。目前,许多互联网用户希望自动连接所有公用事业的互联网。IPv6网络中支持移动用户数据访问的技术之一是IPv6移动协议。在可移动性方面,一个网络范围内的用户可以将该范围移动到另一个网络。对这种技术的高需求将引起黑客或黑客进行攻击的兴趣。其中一种是DoS攻击,这种攻击会使目标妥协,从而拒绝其服务。防火墙通常用于保护网络免受外部攻击。但是,由于防火墙基于攻击者的数据库,未知的可能不会被检测到。为了解决这个障碍,可以使用一种检测工具。在本研究中,IDS作为入侵检测工具与防火墙集成在IPv6 Mobile中实现,以阻止DoS攻击。实验结果表明,该集成系统在对应节点的阻断时间为0.9 s,在主代理节点的阻断时间为1.2 s。当移动节点在本地代理时,被阻断的网络吞吐量减少27.44%,当移动节点在外部网络时,被阻断的网络吞吐量减少28.87%。阻塞攻击的最终结果是将平均CPU利用率降低到30.99%。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信