DocumentCode :
3643154
Title :
Practical IPv6 monitoring-challenges and techniques
Author :
Matěj Grégr;Petr Matoušek;Miroslav Švéda;Tomá?š Podermański
Author_Institution :
Brno University of Technology, Faculty of Information Technology, Bož
fYear :
2011
fDate :
5/1/2011 12:00:00 AM
Firstpage :
650
Lastpage :
653
Abstract :
Network monitoring is an essential task of network management. Information obtained by monitoring devices gives a real picture of the network in production including transmitted data volumes, top hosts, a list of frequently used applications etc. Deep analysis of data collected by monitoring can reveal network attacks or detect misuse of network services. In addition, Data Retention Act requires each ISP to track user´s activities. Protocol IPv6 puts new challenges for network administrators in the context of user identification. Unlike IPv4, an IPv6 address no longer uniquely identifies a user or PC. IPv6 address can be randomly generated and keeps changing in time. PCs with IPv6 stack can also communicate via predefined tunnels over IPv4 infrastructure. That tunneled traffic mostly bypasses network security implemented via firewalls. In this paper, we identify major monitoring and security issues of IPv6 connectivity and propose a solution based on SNMP and Netflow data that helps to uniquely identify users. The solution requires an extended set of monitoring data to be collected from network devices. We present a new data structure based on extended Netflow records. Feasibility of the approach is demonstrated on the Brno University of Technology (BUT) campus network.
Keywords :
"Monitoring","Switches","Tunneling","Neodymium","Filtering","Payloads","Information services"
Publisher :
ieee
Conference_Titel :
Integrated Network Management (IM), 2011 IFIP/IEEE International Symposium on
ISSN :
1573-0077
Print_ISBN :
978-1-4244-9219-0
Type :
conf
DOI :
10.1109/INM.2011.5990647
Filename :
5990647
Link To Document :
بازگشت