• Title/Summary/Keyword: IPv6 Network

Search Result 466, Processing Time 0.028 seconds

Configuring Hosts to Auto-detect (IPv6, IPv6-in-IPv4, or IPv4) Network Connectivity

  • Hamarsheh, Ala;Goossens, Marnix;Alasem, Rafe
    • KSII Transactions on Internet and Information Systems (TIIS)
    • /
    • v.5 no.7
    • /
    • pp.1230-1251
    • /
    • 2011
  • This document specifies a new IPv6 deployment protocol called CHANC, which stands for Configuring Hosts to Auto-detect (IPv6, IPv6-in-IPv4, or IPv4) Network Connectivity. The main part is an application level tunneling protocol that allows Internet Service Providers (ISPs) to rapidly start deploying IPv6 service to their subscribers whom connected to the Internet via IPv4-only access networks. It carries IPv6 packets over HTTP protocol to be transmitted across IPv4-only network infrastructure. The key aspects of this protocol are: offers IPv6 connectivity via IPv4-only access networks, stateless operation, economical solution, assures most firewall traversal, and requires simple installation and automatic configuration at customers' hosts. All data packets and routing information of the IPv6 protocol will be carried over the IPv4 network infrastructure. A simple application and a pseudo network driver must be installed at the end-user's hosts to make them able to work with this protocol. Such hosts will be able to auto-detect the ISP available connectivity in the following precedence: native IPv6, IPv6-in-IPv4, or no IPv6 connectivity. Because the protocol does not require changing or upgrading customer edges, a minimal cost in the deployment to IPv6 service should be expected. The simulation analysis showed that the performance of CHANC is pretty near to those of native IPv6, 6rd, and IPv4 protocols. Also, the performance of CHANC is much better than that of D6across4 protocol.

A Router Auto-Configuration Protocol(RACP) for IPv6 Networks (IPv6 네트워크를 위한 라우터 자동 설정 프로토콜)

  • Lee Wan-Jik;Heo Seok-Yeol
    • Journal of Korea Society of Industrial Information Systems
    • /
    • v.11 no.3
    • /
    • pp.47-58
    • /
    • 2006
  • Address Auto-configuration capability is one of important advantages of IPv6 protocol This function enables the IPv6 hosts to configure IPv6 networks automatically, while IPv6 routers still have to be configured manually. To solve this problem, we propose RACP(Router Auto-Configuration Protocol), a new address auto-configuration protocol which configures all routers of a small network consisting of several routers and sub-networks automatically. The RACP protocol can automatically create and deliver IPv6 prefixes and routing informations of all routers on the network by using the network's prefix assigned by ISP. The proposed RACP can be used to set up network automatically for a small IPv6 site such as a small office network, a home network without the assistance of network administrator.

  • PDF

Exploring Flow Characteristics in IPv6: A Comparative Measurement Study with IPv4 for Traffic Monitoring

  • Li, Qiang;Qin, Tao;Guan, Xiaohong;Zheng, Qinghua
    • KSII Transactions on Internet and Information Systems (TIIS)
    • /
    • v.8 no.4
    • /
    • pp.1307-1323
    • /
    • 2014
  • With the exhaustion of global IPv4 addresses, IPv6 technologies have attracted increasing attentions, and have been deployed widely. Meanwhile, new applications running over IPv6 networks will change the traditional traffic characteristics obtained from IPv4 networks. Traditional models obtained from IPv4 cannot be used for IPv6 network monitoring directly and there is a need to investigate those changes. In this paper, we explore the flow features of IPv6 traffic and compare its difference with that of IPv4 traffic from flow level. Firstly, we analyze the differences of the general flow statistical characteristics and users' behavior between IPv4 and IPv6 networks. We find that there are more elephant flows in IPv6, which is critical for traffic engineering. Secondly, we find that there exist many one-way flows both in the IPv4 and IPv6 traffic, which are important information sources for abnormal behavior detection. Finally, in light of the challenges of analyzing massive data of large-scale network monitoring, we propose a group flow model which can greatly reduce the number of flows while capturing the primary traffic features, and perform a comparative measurement analysis of group users' behavior dynamic characteristics. We find there are less sharp changes caused by abnormity compared with IPv4, which shows there are less large-scale malicious activities in IPv6 currently. All the evaluation experiments are carried out based on the traffic traces collected from the Northwest Regional Center of CERNET (China Education and Research Network), and the results reveal the detailed flow characteristics of IPv6, which are useful for traffic management and anomaly detection in IPv6.

Security Risks Evaluation based on IPv6 Firewall Rules (IPv6의 방화벽 규칙을 기반으로한 보안위험 평가)

  • Phang, Seong-Yee;Lee, Hoon-Jae;Lim, Hyo-Taek
    • Proceedings of the Korean Institute of Information and Commucation Sciences Conference
    • /
    • 2008.10a
    • /
    • pp.261-264
    • /
    • 2008
  • IPv6 has been proposed and deployed to cater the shortage of IPv4 addresses. It is expected to foresee mobile phones, pocket PCs, home devices and any other kind of network capable devices to be connected to the Internet with the introduction and deployment of IPv6. This scenario will bring in more challenges to the existing network infrastructure especially in the network security area. Firewalls are the simplest and the most basic form of protection to ensure network security. Nowadays, firewalls' usage has been extended from not only to protect the whole network but also appear as software firewalls to protect each network devices. IPv6 and IPv4 are not interoperable as there are separate networking stacks for each protocol. Therefore, the existing states of the art in firewalling need to be reengineered. In our context here, we pay attention only to the IPv6 firewalls configuration anomalies without considering other factors. Pre-evaluation of security risk is important in any organization especially a large scale network deployment where an add on rules to the firewall may affect the up and running network. We proposed a new probabilistic based model to evaluate the security risks based on examining the existing firewall rules. Hence, the network administrators can pre-evaluate the possible risk incurred in their current network security implementation in the IPv6 network. The outcome from our proposed pre-evaluation model will be the possibilities in percentage that the IPv6 firewall is configured wrongly or insecurely where known attacks such as DoS attack, Probation attack, Renumbering attack and etc can be launched easily. Besides that, we suggest and recommend few important rules set that should be included in configuring IPv6 firewall rules.

  • PDF

A Study on Supporting Mobile Network in Mobile IPv6 Environment (Mobile IPv6 환경에서의 Mobile Network 지원에 관한 연구)

  • Cha, Jeong-Seok;Song, Joo-Seok
    • Proceedings of the Korea Information Processing Society Conference
    • /
    • 2003.05b
    • /
    • pp.1305-1308
    • /
    • 2003
  • Mobile Network은 일정한 규모 이상의 이동성을 지원하는 네트워치를 말한다. Mobile IP는 표준 IP에 이동성을 지원하기 위한 기법이다. Mobile IPv4에서는 Mobile Network을 가상적인 하나의 Mobile Node처럼 취급하여 지원이 가능하다. 하지만, Mobile IPv6에서는 몇몇의 문제점으로 인하여 Mobile IPv4에서와 같은 접근이 어렵다. 이 논문에서는 Mobile IPv6환경에서 Mobile Network을 지원할 수 있는 기법을 제안하고 분석하였다.

  • PDF

Design and Implementation of Migration from IPv4 Network to Enterprise IPv6 Network (IP4 Network에서 Enterprise IPv6 Network로의 Migration 설계 및 구현)

  • 이진영;윤일;장경진;오선진
    • Proceedings of the Korea Multimedia Society Conference
    • /
    • 2003.11b
    • /
    • pp.687-690
    • /
    • 2003
  • 오늘날 인터넷을 통한 모든 통신망이 끊임없이 발전하고 있는 가운데 IPv4가 가지는 문제점들이 치명적인 위협으로 대두되고 있다. 따라서, 폭발적인 인터넷 사용자 증가로 인한 IP address의 고갈과 느려져만 가는 인터넷 속도에 대해 대안이 필요하다. IPv4는 32bit 체계로 약 40억 개의 IP 주소를 가지고 있으나, 인터넷 초기의 무분별한 클래스를 사용하여 40억 개보다 적은 양의 주소를 사용 할 수 있게 되었다. IPv6는 128bit의 주소 체계를 가지고 있으며, 3.4 $10^{38}$개의, 천문학적인 주소를 할당 할 수 있으며, 보안성과 서비스 품질보장(QoS), 이동성 기존의 인터넷 속도의 가속 기능 등 다양한 장정들을 가지고 있다. 본 논문에서는 IPv4에서 IPv6로 진화해 가야 하는 시기적인 요소보다는 IPv6로의 공존해 나아가야 하는 기술적인 문제를 극복하기 위해 기존 IPv4망에서 IPv6 주소체계를 지원할 수 있도록 설계하고 Backbone network 구성에 일반적인 구현을 통하여 IGP와 EGP 구간의 라우팅 정보공유에 대하여 논의한다.

  • PDF

Performance analysis of IPv4/IPv6 for Internet application services (인터넷 응용 서비스 제공을 위한 IPv4/IPv6의 성능 분석)

  • 김광수;김광현
    • The Journal of Korean Institute of Communications and Information Sciences
    • /
    • v.29 no.8B
    • /
    • pp.747-754
    • /
    • 2004
  • The Internet is in the phase of transition of IPv6 and the network equipments based on IPv6 are released. A lot of investments are done in development of network equipments but important thing is service technology. And a various experiments are performed for this service technology. However, the performance measurements of a router between IPv4 and nv6 networks are mainly focused. Therefore, the performance measurement of Internet application services need to be done. In this paper, we show the performance analysis results that the Internet application services are provided regardless of network infra and protocols. As a result, we know that the efficiency of dual networks is lower than the native network for the Internet application services.

A Security Vulnerability in IPv6 Native Network and Mixed IPv4/IPv6 Network (IPv6 순수망과 IPv4/IPv6 혼재망의 보안 취약점)

  • Yi Young-Soo;Park Nam-Youl;Kim Yong-Min;Noh Bong-Nam
    • Proceedings of the Korea Institutes of Information Security and Cryptology Conference
    • /
    • 2006.06a
    • /
    • pp.340-343
    • /
    • 2006
  • IPv6는 차세대 네트워크를 구축하기 위한 가장 핵심적인 기술로써, 풍부한 주소공간과 이동성 지원, 보안기능 강화 등 IPv4에 비해 많은 이점을 지니고 있다. 또한 IPv4의 주소 고갈 문제를 해결하기 위해 IPv6로의 전환이 당연시 되고 있으나 IPv4/IPv6 혼재망이 과도기적인 입장에서 대안이 될 수 있다. 그러나 IPv4/IPv6 혼재망과 IPv6망은 IPv4에서와 마찬가지로 프로토콜 기능상의 많은 문제점을 안고 있다. 본 논문에서는 IPv6망 및 IPv4/IPv6 혼재 네트워크상에서의 보안 취약점과 실험 결과를 기술하였다.

  • PDF

A study of IPv6-based NGI network and application Interworking over TEIN(TransEurasia Information Network) (한-EU간 트랜스유라시아 망 기반의 IPv6 기반 차세대인터넷 망 및 응용 연동 연구)

  • 이승윤;김형준;박기식
    • Proceedings of the Korean Institute of Information and Commucation Sciences Conference
    • /
    • 2002.11a
    • /
    • pp.569-574
    • /
    • 2002
  • TransEurasia Information Network(TEIN) was established at December 2001, which is a kind of continental network between Korean and Europe. For promoting the TEIN, ETRI has developed the IPv6-based NGI network and applications since early of 2001, and also trying to apply the results into TEIN. With this results for IPv6 research and development as well as its experiences, we can verify the IPv6 related technology and applications on the TEIN as a NGI infrastructure.

  • PDF

A Design of SERDL(Security Evaluation Rule Description Language) and Rule Execution Engine for Evaluating Security of IPv6 Network (IPv6 네트워크 계층의 보안성 평가를 위한 평가규칙 표기 언어 및 평가 수행기의 설계)

  • Kwon, Hyeok-Chan;Kim, Sang-Choon
    • The KIPS Transactions:PartC
    • /
    • v.11C no.4
    • /
    • pp.471-484
    • /
    • 2004
  • Recently. many projects have been actively implementing IPsec on the various Operating Systems for security of IPv6 network. But there is no existing tool that checks the IPsec-based systems, which provide IPsec services, work Properly and provide their network security services well In the IPv6 network. In this paper, we design SERDL(Security Evaluation Rule Description Language) and rule execution tool for evaluating security of the IPv6 network, and we provide implementation details. The system Is divided into following parts : User Interface part, Rule Execution Module part, DBMS part and agent that gathering information needed for security test.