摘要
经过对IPv6数据包报头格式的研究,提出了基于限制性策略的IPv6报头安全性检测算法。该算法根据IPv6协议规范和网络安全需求,按照各扩展报头的出现顺序、扩展报头和/或选项的组合构造及重复次数的特性来检测有潜在安全威胁的恶意IPv6数据包。实验结果表明,该算法有效且能够在一定程度上增强安全防护设备的检测能力。
Through the study on IPv6 header structure,this paper designed a new algorithm for detecting IPv6 packet header security based on restrictive policies.Based on the extension header ordering,certain prohibited combinations and duplicate of header and/or options,this algorithm could detect the potentially malicious packets,depending on IPv6 protocol specifications and network security needs.The experimental results show that the algorithm can detect the threats correctly and efficiently,and can give protection facilities a better ability to detect unwanted packets.
出处
《计算机应用研究》
CSCD
北大核心
2012年第4期1409-1412,1416,共5页
Application Research of Computers
基金
国家重点基础研究发展计划资助项目(2007CB307102)
国家高技术研究发展计划资助项目(2007AA01Z2A1)