Effectiveness of security tools to anomalies on tunneled traffic

Tunneling Mechanism has been proven as an option to link the communication between IPv6 network and IPv4 environment without incurring the high cost of upgrading equipment. However, this mechanism has reduced the network performance and downgrade the level of security if compared to the native IPV6...

Full description

Saved in:
Bibliographic Details
Main Authors: Bahaman, Nazrulazhar, Abdollah, Mohd Faizal, Mas'ud, Mohd Zaki, Anton Satria, Prabuwono
Format: Article
Language:English
Published: Asian Network for Scientefic Information 2012
Subjects:
Online Access:http://eprints.utem.edu.my/id/eprint/6773/1/191-199.pdf
http://eprints.utem.edu.my/id/eprint/6773/
https://docsdrive.com/pdfs/ansinet/itj/2012/191-199.pdf
Tags: Add Tag
No Tags, Be the first to tag this record!
Description
Summary:Tunneling Mechanism has been proven as an option to link the communication between IPv6 network and IPv4 environment without incurring the high cost of upgrading equipment. However, this mechanism has reduced the network performance and downgrade the level of security if compared to the native IPV6 network. The Transition Mechanism has also become a covert channel for spreading threats without being acknowledged by the network security tools. Even though the issues have been raised in the set of IETF rules, still they do not provide any recommendation to overcome the problem. Based on this reason, this study explored the effectiveness of conventional network security tools to detect any anomalies occurring on a tunnelling mechanism especially against packet flooding attack in IPv6 tunneling. In order to achieve this objective, a testbed has been deployed with conventional firewall and IDS is used to simulated the IPv6 to IPv4 tunneling mechanism, several network attacks are then launched and the network traffic is then captured to be analysed. The result shows that the firewall with the default setting had blocked all the tunneling packet, while the firewall and IDS with the default rule of set had performed will in IPv4 but not in the IPv6 tunnel