摘要
IPv6协议把IPSec协议作为必选的协议,保证数据在不安全的网络上进行安全传输,使网络层的安全性得到增强,但是无法有效防止针对协议本身的攻击,因此在以IPv6为基础的下一代因特网中,安全问题依然重要。本文通过讨论IP分片攻击的表现形式、IPv6分片重组机制,给出了IPv6分片重组在Snort的具体实现方案。
As a required protocol for IPv6,IPSec ensures data transmission securitily,which makes the network layer enhanced.But IPsec can not prevent attacking against the protocol itself.So security remains important in Internet based on IPv6.This paper discusses the form of fragment attack and fragment reassembling mechanism in IPv6,and then shows the implementation of fragment reassembling mechanism in Snort.
出处
《网络安全技术与应用》
2010年第7期88-90,共3页
Network Security Technology & Application