Perimeter Security Concerns.
Addressing. IPv6 is more flexible in its approach to dynamic addressing. Instead
of solely relying on DHCP, an IPv6 device can address itself through stateless address autoconfiguration (SLAAC). The host uses a unique identifier (typically its own Message Authentication Code (MAC) address) in addition to the Neighbor Discovery (ND) protocol to complete the automatic addressing. Since there is no authentication requirement, the GSD must prevent external devices from attempting to act as an internalrouter during the addressing process.
The significant increase of available addresses in any particular IPv6 network makes it infeasible to discover devices and network topology using traditional port scanning methodologies. By using the multicast listener discovery (MLD) protocol, an attacker can send a probe to the link-local multicast address (ff02::1) and listen for responses. The GSD must block this capability at the perimeter to prevent external devices from attempting to discover internal host sand topologies.
Thursday, April 27, 2017
Subscribe to:
Post Comments (Atom)
The Proliferation of Digital Authoritarianism: An Exhaustive Analysis of the GFW Data Leak
I. Executive Summary A massive and unprecedented data leak, comprising over 500 gigabytes of source code, internal communications, and ope...
-
Summarization of hundreds of comments on Reddit. Ineffective Service: The users explicitly states, "Confirmed that it doesn't w...
-
Based on a review of the provided Privacy Policy , here are some potential legal implications and issues that should be addressed: Scope a...
No comments:
Post a Comment