针对IPv6自身暴露出来的安全缺陷,以开源Snort平台为基础进行了相关研究。依据IPv6的特征,采用IPv6分析技术,针对当前开源入侵检测系统Snort中无法检测IPv6网络中邻居发现协议攻击行为的问题,研究与设计了能对IPv6中邻居发现协议攻击进行检测的HDU_IPv6_IDS入侵检测系统。
According to the security flaws exposed by IPv6, the research based on open source Snort platform was introduced. The research was based on the characteristics of the IPv6 and adopted IPv6 analysis technology. Aiming at solving the problem that the attack behavior of discovery protocol for IPv6 network neighbors cannot be detected in the current open source intrusion detection system Snort. The HDU_IPv6 IDS intrusion detection system was researched and designed which could detect the attacks of neighbor discovery protocol in IPv6.