Integration of Firewall and IDS on Securing Mobile IPv6

S. Praptodiyono, Moh. Jauhari, R. Fahrizal, I. Hasbullah, A. Osman, Shafiq Ul Rehman
{"title":"Integration of Firewall and IDS on Securing Mobile IPv6","authors":"S. Praptodiyono, Moh. Jauhari, R. Fahrizal, I. Hasbullah, A. Osman, Shafiq Ul Rehman","doi":"10.1109/ICIEE49813.2020.9277354","DOIUrl":null,"url":null,"abstract":"The number of Mobile device users in the word has evolved rapidly. Many internet users currently want to connect the internet for all utilities automatically. One of the technologies in the IPv6 network, which supports data access from moving users, is IPv6 Mobile protocol. In its mobility, the users on a range of networks can move the range to another network. High demand for this technology will interest to a hacker or a cracker to carry out an attack. One of them is a DoS attack that compromises a target to denial its services. A firewall is usually used to protect networks from external attacks. However, since the firewall based on the attacker database, the unknown may not be detected. In order to address the obstacle, a detection tool could be used. In this research, IDS as an intrusion detection tool was integrated with a firewall to be implemented in IPv6 Mobile to stop the DoS attack. The results of some experiments showed that the integration system could block the attack at 0.9 s in Correspondent Node and 1.2 s in Home Agent. The blocked attack can decrease the network throughput up to 27.44% when a Mobile Node in Home Agent, 28,87% when the Mobile Node in a Foreign Network. The final result of the blocked attack is reducing the average CPU utilization up to 30.99%.","PeriodicalId":127106,"journal":{"name":"2020 2nd International Conference on Industrial Electrical and Electronics (ICIEE)","volume":null,"pages":null},"PeriodicalIF":0.0000,"publicationDate":"2020-10-20","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2020 2nd International Conference on Industrial Electrical and Electronics (ICIEE)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICIEE49813.2020.9277354","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

The number of Mobile device users in the word has evolved rapidly. Many internet users currently want to connect the internet for all utilities automatically. One of the technologies in the IPv6 network, which supports data access from moving users, is IPv6 Mobile protocol. In its mobility, the users on a range of networks can move the range to another network. High demand for this technology will interest to a hacker or a cracker to carry out an attack. One of them is a DoS attack that compromises a target to denial its services. A firewall is usually used to protect networks from external attacks. However, since the firewall based on the attacker database, the unknown may not be detected. In order to address the obstacle, a detection tool could be used. In this research, IDS as an intrusion detection tool was integrated with a firewall to be implemented in IPv6 Mobile to stop the DoS attack. The results of some experiments showed that the integration system could block the attack at 0.9 s in Correspondent Node and 1.2 s in Home Agent. The blocked attack can decrease the network throughput up to 27.44% when a Mobile Node in Home Agent, 28,87% when the Mobile Node in a Foreign Network. The final result of the blocked attack is reducing the average CPU utilization up to 30.99%.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
防火墙与入侵检测集成在移动IPv6安全中的应用
世界上移动设备用户的数量发展迅速。目前,许多互联网用户希望自动连接所有公用事业的互联网。IPv6网络中支持移动用户数据访问的技术之一是IPv6移动协议。在可移动性方面,一个网络范围内的用户可以将该范围移动到另一个网络。对这种技术的高需求将引起黑客或黑客进行攻击的兴趣。其中一种是DoS攻击,这种攻击会使目标妥协,从而拒绝其服务。防火墙通常用于保护网络免受外部攻击。但是,由于防火墙基于攻击者的数据库,未知的可能不会被检测到。为了解决这个障碍,可以使用一种检测工具。在本研究中,IDS作为入侵检测工具与防火墙集成在IPv6 Mobile中实现,以阻止DoS攻击。实验结果表明,该集成系统在对应节点的阻断时间为0.9 s,在主代理节点的阻断时间为1.2 s。当移动节点在本地代理时,被阻断的网络吞吐量减少27.44%,当移动节点在外部网络时,被阻断的网络吞吐量减少28.87%。阻塞攻击的最终结果是将平均CPU利用率降低到30.99%。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Nutrient Film Technique for Automatic Hydroponic System Based on Arduino Performance Evaluation of Body Temperature Data Transmission Using Turbo Codes in 4G-LTE Design of Prototype Measuring Motor Vehicles Velocity Using Hall Effect Sensor Series A-1302 based On Arduino Mega2560 Design of a Microstrip Antenna Array Dual Band Using Stub Method Feasibility Study for Development of Micro Grid System in Rural Island
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1