Monitoring of Tunneled IPv6 Traffic Using Packet Decapsulation and IPFIX (Short Paper)
نویسندگان
چکیده
IPv6 is being deployed but many Internet Service Providers have not implemented its support yet. Most of the end users have IPv6 ready computers but their network doesn’t support native IPv6 connection so they are forced to use transition mechanisms which transports IPv6 packets through IPv4 network. Unfortunately deployment of IPv6 is slow and at this rate, completion of the migration from IPv4 to IPv6 will take several years. Until then tunneled IPv6 traffic will be present on most networks. This means possible security risk because many of nowadays network tools and firewalls just see IPv4 traffic and content of the encapsulated IPv6 traffic is hidden. We do not know, what kind of traffic is inside of these tunnels, which services are used and if the traffic does not bypass security policy. This paper proposes an approach, how to monitor IPv6 tunnels even on high-speed networks. The contribution of this approach is a possibility of monitoring what is inside IPv6 tunnels. This gives network administrators a way to detect security threats which would be otherwise considered as harmless IPv4 traffic. This approach is also suitable for long term network monitoring. This is achieved by the usage of IPFIX (IP Flow Information Export) as the information carrying format. The proposed approach also allows to monitor traffic on 10 Gbps links, because it supports hardware-accelerated packet distribution to multiple processors. A system based on the proposed approach is deployed at the CESNET2 network, which is the largest academic network in the Czech Republic. This paper also presents statistics about tunneled traffic on the CESNET2 backbone links.
منابع مشابه
Experiences with IPFIX-based Traffic Measurement for IPv6 Networks
Though the popular Cisco NetFlow is widely used for flow-level traffic measurement in IPv4 networks, it is not suitable for IPv6 networks because of the fixed flow structure that cannot carry IPv6-related information. Therefore, the IETF IP Flow Information eXport (IPFIX) standard that employs the flexible flow template structure has been recently proposed to support various flow-level traffic ...
متن کاملA hybrid load balance mechanism for distributed home agents in mobile IPv6
AbrlmctMobile 1Pt~6 is a key technology in IPv6 to support the mobility of wireless communication terminals. In Mobile IPv6, Home Agents (HAS) are responsible for the registration of Mobile Nodes (MNs) in the home network, and tunneling the data packets to the MNs when the MNs are not reachable through its home IP addresses. However recent research shows that the traffic bottleneck could be for...
متن کاملFlow-Based Detection of IPv6-specific Network Layer Attacks
With a vastly different header format, IPv6 introduces new vulnerabilities not possible in IPv4, potentially requiring new detection algorithms. While many attacks specific to IPv6 have proven to be possible and are described in the literature, no detection solutions for these attacks have been proposed. In this study we identify and characterise IPv6-specific attacks that can be detected using...
متن کاملSignature-aware Traffic Monitoring with IPFIX1
Traffic monitoring is essential for accounting user traffic and detecting anomaly traffic such as Internet worms or P2P file sharing applications. Since typical Internet traffic monitoring tools use only TCP/UDP/IP header information, they cannot effectively classify diverse application traffic, because TCP or UDP port numbers could be used by different applications. Moreover, under the recent ...
متن کاملIPFIX/PSAMP: What Future Standards Can Offer to Network Security
Network security often requires the surveillance of the actual traffic in the network. Methods like signature-based attack detection or the detection of traffic anomalies require input from network measurements. The IETF currently standardizes the IP Flow Information Export (IPFIX) protocol for exporting flow information from routers and probes. The packet sampling (PSAMP) group extends the inf...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2011