机构地区: 北京邮电大学
出 处: 《现代电信科技》 2005年第4期45-49,共5页
摘 要: 在以IPv6为基础的下一代因特网中,安全问题依然重要。就IPv6分片攻击的表现形式、IPv6分片重组机制、如何防范IPv6的分片攻击及其在SNORT中的具体实现展开了讨论。测试结果表明,基于IPv6骨干网的入侵检测系统能正确完成分片包的重组,并检测出隐藏在分层包中的敏感信息。 Security is still important in IPv6-based next generation Internet. This paper discusses the form of IPv6 fragment attack, IPv6 fragment reassembling mechanism, the precaution measures of IPv6 fragment attack and its implementation in SNORT. Test shows that IPv6-backbone-based intruding detection system can reassemble the fragments and detect the sensitive information hidden in the fragments.