• DocumentCode
    1490319
  • Title

    A new worm exploiting IPv6 and IPv4-IPv6 dual-stack networks: experiment, modeling, simulation, and defense

  • Author

    Liu, Ting ; Guan, Xiaohong ; Zheng, Qinghua ; Qu, Yu

  • Author_Institution
    MOE KLINN Lab., Xi´´an Jiaotong Univ., Xi´´an, China
  • Volume
    23
  • Issue
    5
  • fYear
    2009
  • fDate
    9/1/2009 12:00:00 AM
  • Firstpage
    22
  • Lastpage
    29
  • Abstract
    It is commonly believed that the IPv6 protocol can provide good protection against network worms that try to find victims through random address scanning due to its huge address space. However, we discover that there is serious vulnerability in terms of worm propagation in IPv6 and IPv4-IPv6 dual-stack networks. It is shown in this article that a new worm can collect the IPv6 addresses of all running hosts in a local subnet very quickly, leading to accelerated worm propagation. Similar to modeling the self-replicating behaviors of biological viruses, a Species-Patch model and a discrete-time simulator are developed to study how the dual-stack worm spreads in networks with various topologies. It is shown that the worm could propagate in the IPv6 and IPv4-IPv6 dual-stack networks much faster than in the current IPv4 Internet. Several effective defense strategies focusing on network deployment are proposed.
  • Keywords
    IP networks; military communication; radiowave propagation; IPv4-IPv6 dual-stack networks; huge address space; random address scanning; worm exploiting; worm propagation; Acceleration; Biological system modeling; IP networks; Internet; Laboratories; Network topology; Protection; Protocols; Testing; Viruses (medical);
  • fLanguage
    English
  • Journal_Title
    Network, IEEE
  • Publisher
    ieee
  • ISSN
    0890-8044
  • Type

    jour

  • DOI
    10.1109/MNET.2009.5274918
  • Filename
    5274918