W. Ali, A. Taib, N. Hussin, R. Budiarto, J. Othman
{"title":"Distributed security policy for IPv6 deployment","authors":"W. Ali, A. Taib, N. Hussin, R. Budiarto, J. Othman","doi":"10.1109/ISESEE.2011.5977081","DOIUrl":null,"url":null,"abstract":"Internet Protocol version 6 (IPv6) is a next generation protocol that is designed to solve the problem of the current Internet Protocol version 4 (IPv4) depletion. With IPv6, almost anything in the world can be assigned an IPv6 address which makes communication between every single person to another possible. Besides, monitoring and sensing every single node or instrument can be done due to each item has its own IPv6 address. Realizing the features of IPv6, enterprise networks have begun deploying IPv6. Although they have not decided to deploy IPv6, IPv6 packet is possibly already in the network due to the most present operating systems supporting IPv6 and IPv6 enable is set as default. Deploying IPv6 in the existing IPv4 network results in coexistence of both protocols in the network. Thus, the coexistence condition exposed enterprise's network to higher probability of vulnerabilities and attacks. Hence, several security policies should be created to maintain security for both IPv4 and IPv6. A proper mechanism to manage the policies to ensure a secure IPv6 deployment is a necessity. Since enterprises have many branches and counterparts, it is essential to have a mechanism to distribute the policies among their branches or subnets. Therefore, the proper mechanism to distribute the security policy which will also support the green computing environment should be formed.","PeriodicalId":105476,"journal":{"name":"2011 3rd International Symposium & Exhibition in Sustainable Energy & Environment (ISESEE)","volume":"245 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2011-06-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"4","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2011 3rd International Symposium & Exhibition in Sustainable Energy & Environment (ISESEE)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ISESEE.2011.5977081","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 4
Abstract
Internet Protocol version 6 (IPv6) is a next generation protocol that is designed to solve the problem of the current Internet Protocol version 4 (IPv4) depletion. With IPv6, almost anything in the world can be assigned an IPv6 address which makes communication between every single person to another possible. Besides, monitoring and sensing every single node or instrument can be done due to each item has its own IPv6 address. Realizing the features of IPv6, enterprise networks have begun deploying IPv6. Although they have not decided to deploy IPv6, IPv6 packet is possibly already in the network due to the most present operating systems supporting IPv6 and IPv6 enable is set as default. Deploying IPv6 in the existing IPv4 network results in coexistence of both protocols in the network. Thus, the coexistence condition exposed enterprise's network to higher probability of vulnerabilities and attacks. Hence, several security policies should be created to maintain security for both IPv4 and IPv6. A proper mechanism to manage the policies to ensure a secure IPv6 deployment is a necessity. Since enterprises have many branches and counterparts, it is essential to have a mechanism to distribute the policies among their branches or subnets. Therefore, the proper mechanism to distribute the security policy which will also support the green computing environment should be formed.
Internet Protocol version 6 (IPv6)是为解决当前Internet Protocol version 4 (IPv4)耗尽的问题而设计的下一代协议。有了IPv6,世界上几乎任何东西都可以被分配一个IPv6地址,这使得每个人之间的通信成为可能。此外,由于每个项目都有自己的IPv6地址,因此可以对每个单个节点或仪器进行监控和传感。在认识到IPv6的特性后,企业网络已经开始部署IPv6。虽然他们还没有决定部署IPv6, IPv6数据包可能已经在网络中,因为大多数目前的操作系统支持IPv6和IPv6启用设置为默认值。在现有的IPv4网络中部署IPv6,会导致两种协议在网络中共存。因此,这种共存状态将企业网络暴露在更高的漏洞和攻击概率之下。因此,应该创建几个安全策略来维护IPv4和IPv6的安全性。一个适当的机制来管理策略,以确保安全的IPv6部署是必要的。由于企业有许多分支机构和对等机构,因此必须有一种机制在其分支机构或子网之间分发策略。因此,需要形成一种支持绿色计算环境的安全策略分发机制。