Browse > Article
http://dx.doi.org/10.13089/JKIISC.2007.17.6.77

An Improvement of Packet Filtering Functions for Tunneling Based IPv4/IPv6 Transition Mechanisms  

Lee, Wan-Jik (Pusan University)
Heo, Seok-Yeol (Pusan University)
Lee, Won-Yeoul (Youngsan University)
Shin, Bum-Joo (Pusan University)
Abstract
It will need a quite long time to replace IPv4 protocol, which currently used, with IPv6 protocol completely, thus we will use both IPv4 and IPv6 together in the Internet during the period. For coexisting protocols, IETF standardized various IPv4/IPv6 transition mechanisms. However, new security problems of IPsec adaptation and IPv6 packet filtering can be raised by tunneling mechanism which mainly used in transition mechanisms. To resolve these problems, we suggested two improved schemes for packet filtering functions, which consists of an inner header filtering scheme and a dedicated filtering scheme for IPv4/IPv6 transition mechanisms. Also we implemented our proposed schemes based on Linux Netfilter framework, and we tested their filtering functions and evaluated experimental performance of our implementation on IPv4/IPv6 transition testbed. These evaluation tests indicated that our improved packet filtering functions can solve packet filtering problems of IPv4/IPv6 transition mechanisms without severely affecting system performance.
Keywords
IPv6; Tunneling; Packet filtering; security;
Citations & Related Records
Times Cited By KSCI : 1  (Citation Analysis)
연도 인용수 순위
1 신명기, 김형준, 'IPv6 전환 환경에서의 보안 기술 분석,' 전자통신 동향분석 제21권 제5호, pp. 163-170, 2006
2 U. Black, Internet Security Protocols, Prentice Hall PTR, 2000
3 W. Lee, et al., 'A Secure Packet Filtering Mechanism for Tunneling over Internet,' ICESS 2007 LNCS 4523, pp. 641-652, May 2007
4 C. Benevenuti, Understanding LINUX Network Internals, O'REILLY, 2005
5 The 6NET Consortium, 6net: An IPv6 Deployment Guide, September 2005
6 E. Davies, et al., IPv6 Transition Co-existence Security Considerations, draft-ietf-v6ops-security-overview-06.txt, April 2007
7 허석렬 외, 'IPv4/IPv6 터널링 환경에 적합한 패킷 필터링 기능 설계 및 구현,' 정보과학회 논문 지: 정보통신 제33권 6호, pp. 407-419, 2006   과학기술학회마을
8 R.Russell, Linux Netfilter Extension Howto, http://www.netfileter.org/ documentation
9 R. Jones, Care and Feeding of Netperf, http://www.netperf.org/svn/netperf2.html
10 R. Graveman, et al., Using IPsec to Secure IPv6-in-IPv4 Tunnels, draft-ietf-v6ops-ipsectunnels- 05.txt, January 2007