Ipv6中Type 0路由头漏洞的防范算法

Mohit Wadhwa, Manju Khari
{"title":"Ipv6中Type 0路由头漏洞的防范算法","authors":"Mohit Wadhwa, Manju Khari","doi":"10.1109/CICN.2011.133","DOIUrl":null,"url":null,"abstract":"The next generation internet protocol version 6 was developed by the network working group of the Internet Engineering Task Force (IETF), to extend and eventually replace IPv4 capabilities and brings many new features over IPv4 like large address space, flow labelling capabilities, expended address capabilities, demand for real time data transfer, security at IP level and so on. However there are various vulnerabilities reported in contrast to the new features emerging in IPv6. One of the kinds of these vulnerabilities exists in routing header of IPv6. Routing header is a kind of extension header of IPv6 and it's used by an IPv6 source to list one or more intermediate nodes to be visited on the way to a packet destination. But routing header has serious vulnerability and by using this vulnerability attacker can by-pass the security principles at packet filtering system such as router/firewall without breaking the packet filtering rules and than he can access the internal protected network by using routing header. This paper suggests a prevention algorithm that uses with existed packet filtering system and solves the vulnerabilities caused by routing header.","PeriodicalId":292190,"journal":{"name":"2011 International Conference on Computational Intelligence and Communication Networks","volume":"65 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2011-10-07","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":"{\"title\":\"Prevention Algorithm against the Vulnerability of Type 0 Routing Header in Ipv6\",\"authors\":\"Mohit Wadhwa, Manju Khari\",\"doi\":\"10.1109/CICN.2011.133\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"The next generation internet protocol version 6 was developed by the network working group of the Internet Engineering Task Force (IETF), to extend and eventually replace IPv4 capabilities and brings many new features over IPv4 like large address space, flow labelling capabilities, expended address capabilities, demand for real time data transfer, security at IP level and so on. However there are various vulnerabilities reported in contrast to the new features emerging in IPv6. One of the kinds of these vulnerabilities exists in routing header of IPv6. Routing header is a kind of extension header of IPv6 and it's used by an IPv6 source to list one or more intermediate nodes to be visited on the way to a packet destination. But routing header has serious vulnerability and by using this vulnerability attacker can by-pass the security principles at packet filtering system such as router/firewall without breaking the packet filtering rules and than he can access the internal protected network by using routing header. This paper suggests a prevention algorithm that uses with existed packet filtering system and solves the vulnerabilities caused by routing header.\",\"PeriodicalId\":292190,\"journal\":{\"name\":\"2011 International Conference on Computational Intelligence and Communication Networks\",\"volume\":\"65 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2011-10-07\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"2\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2011 International Conference on Computational Intelligence and Communication Networks\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/CICN.2011.133\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2011 International Conference on Computational Intelligence and Communication Networks","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/CICN.2011.133","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2

摘要

下一代互联网协议版本6由互联网工程任务组(IETF)的网络工作组开发,扩展并最终取代IPv4功能,并在IPv4上带来许多新特性,如大地址空间、流标签功能、扩展地址功能、实时数据传输需求、IP级别的安全性等。然而,与IPv6中出现的新特性相比,报告中存在各种漏洞。其中一种漏洞存在于IPv6的路由头中。路由报头是IPv6的一种扩展报头,它被IPv6源用来列出一个或多个在到达数据包目的地的途中要访问的中间节点。但是路由头存在着严重的漏洞,攻击者利用这一漏洞可以在不违反包过滤规则的情况下绕过路由器/防火墙等包过滤系统的安全原则,从而利用路由头访问受保护的内部网络。本文提出了一种与现有包过滤系统结合使用的防范算法,解决了路由头所带来的漏洞。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Prevention Algorithm against the Vulnerability of Type 0 Routing Header in Ipv6
The next generation internet protocol version 6 was developed by the network working group of the Internet Engineering Task Force (IETF), to extend and eventually replace IPv4 capabilities and brings many new features over IPv4 like large address space, flow labelling capabilities, expended address capabilities, demand for real time data transfer, security at IP level and so on. However there are various vulnerabilities reported in contrast to the new features emerging in IPv6. One of the kinds of these vulnerabilities exists in routing header of IPv6. Routing header is a kind of extension header of IPv6 and it's used by an IPv6 source to list one or more intermediate nodes to be visited on the way to a packet destination. But routing header has serious vulnerability and by using this vulnerability attacker can by-pass the security principles at packet filtering system such as router/firewall without breaking the packet filtering rules and than he can access the internal protected network by using routing header. This paper suggests a prevention algorithm that uses with existed packet filtering system and solves the vulnerabilities caused by routing header.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信