期刊文献+

基于SNORT的IPv6入侵检测系统的研究与实现 被引量:9

Research and Development of IPv6 IDS Based on SNORT
下载PDF
导出
摘要 本文探讨了实现IPv6入侵检测系统的关键技术——规则构造和解析、IPv6包结构解析、IPv6快速规则匹配、IPv6分段重组、对过渡技术的支持、兼容IPv4等,并以SNORT的最新版本V2.2为基础实现了一个支持IPv4、IPv6和过渡技术的入侵检测系统。通过测试,该入侵检测系统能够检测出各种常见的IPv6入侵行为,在最小包长情况下能达到百兆比特每秒线速。 Intrusion detection technology,the second protection barrier beyond firewall, is one of the most important network security technologies. After several years' development, IPv6 is becoming maturity. It is necessary and urgent to research and develop the intrusion detection system (IDS) under IPv6 environment. SNORT, written in C, is a well-known, open source, lightweight network intrusion detection system. SNORT supports various hardware and software platforms and has been a research paradigm of IDS for its clear structure, easy extensibility owed to the plug-in mechanism. This paper discusses the key technologies related to IPv6 IDS, including rules construction and parsing, IPv6 packet decoding and fast matching, IPv6 fragmentation and reassembly, transition technologies support and IPv4 compatible, etc.. An IPv6 IDS, based on SNORT2.2, the latest version, is accomplished, which supports IPv4, IPv6 and transition technologies. By testing, this IDS, on the one hand, can detect various IPv6 intrusions; on the other hand, as for the performance, this IDS can reach the line speed under the hybrid traffic of IPv4 and IPv6 of the minimum packets.
出处 《电信科学》 北大核心 2005年第8期32-36,共5页 Telecommunications Science
基金 国家网络与信息安全技术专项资助项目(No.2004-研1-917-C-022)
关键词 入侵检测系统 IPV6 SNORT 过渡技术 快速匹配算法 结构解析 IPV4 规则匹配 最新版本 通过测试 intrusion detection system, IPv6, SNORT, transition technology, fast matching algorithm
  • 相关文献

参考文献14

  • 1John Stenbit. Internet protocol version 6. Department of Defense, June 20O3.
  • 2.[EB/OL].http://www.snort.org,.
  • 3Wu Sun, Udi Manber. A fast algorithm for multi-pattern searching. The Computer Science Department, The University of Arizona, Technical Report, 1994.
  • 4Deering S, Hinden R. Internet protocol version 6 specification.RFC2460, December 1998.
  • 5Conta A, Deering S. Internet control message protocol for the Internet protocol version 6 specification. RFC2463, December 1998.
  • 6Narten T, Nordmark E, Simpson W. Neighbor discovery for IP version 6. RFC2461, December 1998.
  • 7Gilligan R, Nordmark E. Transition mechanisms for IPv6 hosts and routers. RFC2893, August 2000.
  • 8McCann J, Deering S, Mogul J. Path MTU discovery for IP version 6.RFC1981, August 1996.
  • 9Charles Hornig. A standard for the transmission of IP datagrams over Ethernet networks. RFC894, April 1984.
  • 10Crawford M. Transmission of IPv6 packets over Ethernet networks.RFC2464, December 1998.

共引文献7

同被引文献38

引证文献9

二级引证文献10

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部