Risk assessment equation for IPv6 network / Athirah Rosli

Exposure to risk due to the implementation of IPv6 has made enterprise networks take immediate actions to avoid misrepresenting of risks and applying inadequate countermeasures. Being aware of the needs to calculate the risk of IPv6 threats and vulnerabilities, enterprises demand a proper equation t...

Full description

Saved in:
Bibliographic Details
Main Author: Rosli, Athirah
Format: Thesis
Language:en
Published: 2017
Subjects:
Online Access:https://ir.uitm.edu.my/id/eprint/37209/1/37209.pdf
https://ir.uitm.edu.my/id/eprint/37209/
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1833065570121023488
author Rosli, Athirah
author_facet Rosli, Athirah
author_sort Rosli, Athirah
building Tun Abdul Razak Library
collection Institutional Repository
content_provider Universiti Teknologi Mara
content_source UiTM Institutional Repository
continent Asia
country Malaysia
description Exposure to risk due to the implementation of IPv6 has made enterprise networks take immediate actions to avoid misrepresenting of risks and applying inadequate countermeasures. Being aware of the needs to calculate the risk of IPv6 threats and vulnerabilities, enterprises demand a proper equation that is flexible to represent risks of the network. Unfortunately, the existing risk assessment equation is insufficient because it calculates risk per asset rather than the network as a whole. The current risk assessment equation also fails to relate security requirements with the dependencies of asset, threat and vulnerability. By using grounded theory, it is realized that confidentiality, integrity, and availability are important elements to be considered in risk assessment. Thus, this research proposes new risk assessment equation for IPv6 deployment that includes base score value that considers security goal of the network. The developed equation was validated via experimentation that involved testing the UDP flooding attack, TCP flooding attack and multicast attack by using OMNeT++. Result shows that the IRA6 equation is adequate in determining the risk value compared to the exvisting risk assessment equation. The risk values are associated into IPv6 threat model for future reference and as preliminary information for enterprise network. With the added information, it can be used by network administrators in their decision making and strategic planning for network security. Further research can include other elements in security goals which are nonrepudiation, authentication, authorization and accountability.
format Thesis
id my.uitm.ir-37209
institution Universiti Teknologi Mara
language en
publishDate 2017
record_format eprints
spelling my.uitm.ir-372092022-11-01T09:19:31Z https://ir.uitm.edu.my/id/eprint/37209/ Risk assessment equation for IPv6 network / Athirah Rosli Rosli, Athirah Computer networks. General works. Traffic monitoring TCP/IP (Computer network protocol) Exposure to risk due to the implementation of IPv6 has made enterprise networks take immediate actions to avoid misrepresenting of risks and applying inadequate countermeasures. Being aware of the needs to calculate the risk of IPv6 threats and vulnerabilities, enterprises demand a proper equation that is flexible to represent risks of the network. Unfortunately, the existing risk assessment equation is insufficient because it calculates risk per asset rather than the network as a whole. The current risk assessment equation also fails to relate security requirements with the dependencies of asset, threat and vulnerability. By using grounded theory, it is realized that confidentiality, integrity, and availability are important elements to be considered in risk assessment. Thus, this research proposes new risk assessment equation for IPv6 deployment that includes base score value that considers security goal of the network. The developed equation was validated via experimentation that involved testing the UDP flooding attack, TCP flooding attack and multicast attack by using OMNeT++. Result shows that the IRA6 equation is adequate in determining the risk value compared to the exvisting risk assessment equation. The risk values are associated into IPv6 threat model for future reference and as preliminary information for enterprise network. With the added information, it can be used by network administrators in their decision making and strategic planning for network security. Further research can include other elements in security goals which are nonrepudiation, authentication, authorization and accountability. 2017 Thesis NonPeerReviewed text en https://ir.uitm.edu.my/id/eprint/37209/1/37209.pdf Risk assessment equation for IPv6 network / Athirah Rosli. (2017) Masters thesis, thesis, Universiti Teknologi MARA (UiTM).
spellingShingle Computer networks. General works. Traffic monitoring
TCP/IP (Computer network protocol)
Rosli, Athirah
Risk assessment equation for IPv6 network / Athirah Rosli
title Risk assessment equation for IPv6 network / Athirah Rosli
title_full Risk assessment equation for IPv6 network / Athirah Rosli
title_fullStr Risk assessment equation for IPv6 network / Athirah Rosli
title_full_unstemmed Risk assessment equation for IPv6 network / Athirah Rosli
title_short Risk assessment equation for IPv6 network / Athirah Rosli
title_sort risk assessment equation for ipv6 network / athirah rosli
topic Computer networks. General works. Traffic monitoring
TCP/IP (Computer network protocol)
url https://ir.uitm.edu.my/id/eprint/37209/1/37209.pdf
https://ir.uitm.edu.my/id/eprint/37209/
url_provider http://ir.uitm.edu.my/