• DocumentCode
    1679063
  • Title

    Dynamic Network Separation for IPv6 Network Security Enhancement

  • Author

    Suzuki, Satoshi ; Kondo, Satoshi

  • Author_Institution
    Hitachi, Ltd.
  • fYear
    2005
  • Firstpage
    22
  • Lastpage
    25
  • Abstract
    Currently on the Internet, a network site is often secured by a firewall, filtering bogus traffic from outside at the border of the network site. This ’Border Defence Model’, however, obstructs the deployment of IPv6 applications and services, because the firewall negates the benefits of IPv6, such as end-to-end communication and IPsec. To solve this problem, the ’Quarantine Model’ is proposed. In this model, network nodes are accommodated to separate network segments according to their security levels, and a different security policy is implemented on each network segment. This ’divide and conquer’ framework provides more flexible and better network security for the Quarantine Model. This paper discusses how to conduct dynamic network separation, which is mandatory to the Quarantine Model, and analyzes the pros and cons of separation methods.
  • Keywords
    Data security; IP networks; Laboratories; Level measurement; Network servers; Poles and towers; Protection; Protocols; TCPIP; Telecommunication traffic;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Applications and the Internet Workshops, 2005. Saint Workshops 2005. The 2005 Symposium on
  • Print_ISBN
    0-7695-2263-7
  • Type

    conf

  • DOI
    10.1109/SAINTW.2005.1619969
  • Filename
    1619969