计算机与现代化 ›› 2021, Vol. 0 ›› Issue (02): 122-126.

• 信息安全 • 上一篇    

抗灰洞攻击的IPv6网络部署改造方法

  

  1. (广东电力信息科技有限公司,广东广州510080)
  • 出版日期:2021-03-01 发布日期:2021-03-01
  • 作者简介:陈守明(1986—),男,湖北钟祥人,高级工程师, 硕士,研究方向:网络安全,E-mail: chenshouming@gdxx.csg.cn; 梁运德(1987—),男,广东河源人, 高级工程师,本科,研究方向:网络工程,E-mail: liangyunde@gdxx.csg.cn; 钱扬(1973—),男,浙江桐乡人,高级工程师,本科,研究方向:网络安全管理; 李雪武(1989—),男,广东梅州人,硕士,研究方向:图像处理; 卢妍倩(1993—),女,广东揭阳人,助理工程师,本科,研究方向:电子信息科学与技术。

IPv6 Network Deployment and Transformation Method Against Grey Hole Attack

  1. (Guangdong Power Information Technology Co. Ltd., Guangzhou 510080, China)
  • Online:2021-03-01 Published:2021-03-01

摘要: 针对原有IPv6网络部署改造方法对于灰洞攻击检测能力较差,导致IPv6网络攻击预警能力较差的问题,设计一种抗灰洞攻击的IPv6网络部署改造方法。采用层次化的设计理念,将网络构架从逻辑角度分为核心层、汇聚层、接入层以及广域网与服务器的接入部分,以网络构架为基础,优化网络中使用的服务器群以及网络间接方式。设定网络检测匹配规则,将接入方式作为网络中路由器的间接方法,针对多模式网络攻击,应用多模式检测方法实现IPv6网络攻击检测。实验结果表明,本文方法的灰洞攻击预警能力较强,操作系统的兼容性较高。

关键词: IPv6, 过渡技术, IP协议, 灰洞攻击, 网络部署

Abstract: In view of the poor detection ability of the original IPv6 network deployment and transformation method for gray hole attack, which results in the poor early warning ability of IPv6 network attack, this paper designs an IPv6 network deployment and transformation method against gray hole attack. The network architecture is divided into core layer, convergence layer, access layer, and access part of Wan and server from a logical point of view by adopting hierarchical design concept. Based on the network architecture, the server cluster used in the network and network indirect mode are optimized. The paper sets network detection and matching rules, uses access mode as an indirect method of routers in the network, against multi-mode network attack, uses multi-mode detection method to achieve IPv6 network attack detection. The experimental results show that the designed method has strong early warning ability of gray hole attack and high compatibility of operating system.

Key words: IPv6, transition technology, IP protocol, grey hole attack, network deployment