跳到主要导航 跳到搜索 跳到主要内容

A new worm exploiting IPv4-IPv6 dual-stack networks

  • Tsinghua University
  • Xi'an Jiaotong University

科研成果: 书/报告/会议事项章节会议稿件同行评审

6 引用 (Scopus)

摘要

It is commonly believed that the IPv6 protocol can provide good protection against network worms due to its huge address space. However, it is proved to be incorrect by our study on the new "dual-stack worm" which can spread in IPv4-IPv6 dual-stack networks. It is found in this paper that the dual-stack worm can collect the IPv6 addresses of all running hosts on the link-local quickly and effectively, which may result in accelerated worm spreading on the IPv6 link-locals. This worm applies a two-level scanning mechanism to find its targets in dual-stack networks, which is investigated by exploring its similarity to the self-replicating behaviors of biological viruses. Based on the ideas of classifying the population into different species or patches, we categorized all vulnerable hosts into two species and separated all dual-stack hosts into several patches to model the propagation of this worm by differential equations. Simulation is performed to validate the worm propagation model and to study the propagation of the worm in various dual-stack networks with different patch parameters. The simulation results show that the worm is able to spread much faster in IPv4-IPv6 dual-stack network than that in the pure IPv4 Internet. It is also noted that the dual-stack links may influence the propagation of the worm in the Internet.

源语言英语
主期刊名WORM'07 - Proceedings of the 2007 ACM Workshop on Recurring Malcode
9-15
页数7
DOI
出版状态已出版 - 2007
活动2007 ACM Workshop on Recurring Malcode, WORM'07 - Alexandria, VA, 美国
期限: 2 11月 20072 11月 2007

出版系列

姓名WORM'07 - Proceedings of the 2007 ACM Workshop on Recurring Malcode

会议

会议2007 ACM Workshop on Recurring Malcode, WORM'07
国家/地区美国
Alexandria, VA
时期2/11/072/11/07

学术指纹

探究 'A new worm exploiting IPv4-IPv6 dual-stack networks' 的科研主题。它们共同构成独一无二的指纹。

引用此