IzzyMenu.com

SECURITY °ü·Ã ÀÚ·á °­ÀÇ ÀÚ·á

 ·Î±×ÀÎ  È¸¿ø°¡ÀÔ

[IPv6] 6To4 °ø°Ý±â¹ý
ANTON  2010-08-11 18:02:34, Á¶È¸ : 183, Ãßõ : 51

1. Why we need the 6to4 mechanism in the internet?

- IPv6¿Í IPv4´Â ÁÖ¼Òü°è¸¦ Æ÷ÇÔÇÑ ÀüüÀûÀÎ ÇÁ·ÎÅäÄÝÀÌ ´Ù¸£´Ù. µ¿½Ã¿¡ IPv4³×Æ®¿öÅ©¸¦ ¾ø¾Ö°í IPv6·Î ¾÷±×·¹µåÇϱ⿡´Â ºñ¿ëÀÌ ³Ê¹« Å©±â ¶§¹®¿¡, IPv4 ³×Æ®¿öÅ©¿Í IPv6 ³×Æ®¿öÅ©ÀÇ °øÁ¸À» À§ÇÑ »óÈ£°£ÀÇ ÁÖ¼Ò Àüȯ ¹æ¹ýÀÌ ÇÊ¿äÇÏ´Ù. 6to4´Â ÀÌ·¯ÇÑ ÁÖ¼Ò Àüȯ ±â¹ý ÁßÀÇ Çϳª·Î½á Åͳθµ ±â¹ýÀ» ÀÌ¿ëÇÑ´Ù. 6to4´Â IPv6 ³×Æ®¿öÅ© »çÀÌÀÇ IPv6 6to4 prefix¾È¿¡´Ù IPv4 ÁÖ¼Ò¸¦ ³Ö¾î¼­ ĸ½¶È­ ÇÔÀ¸·Î½á µÎ ÇÁ·ÎÅäÄÝÀÇ ¿¬µ¿¹æ¾ÈÀ» Á¦½ÃÇÏ°í ÀÖ´Ù.(ex. 9.0.0.1 => 2002:0900:0001::1 )

<!--[if !supportEmptyParas]-->



<!--[endif]-->
2. Explain how to communicate between an IPv6 native host and a 6to4 host.

(1) IPv6 native host°¡ 6to4 ÁÖ¼ÒÇüŸ¦ »ç¿ëÇÑ IPv6 ÆÐŶÀ» 6to4 ¶ó¿ìÅÍ·Î Àü¼Û

(2) 6to4 ¶ó¿ìÅÍ´Â ÆÐŶ¿¡¼­ 6to4 ÁÖ¼Ò¿¡ Æ÷ÇÔµÈ IPv4 ÁÖ¼Ò¸¦ ÃßÃâ

(3) ÃßÃâÇÑ IPv4 ÁÖ¼Ò·Î IPv4 Çì´õ¸¦ ±¸¼ºÇÏ¿© IPv4-in-IPv6 ÇüÅ·ΠÆÐŶÀ» ÀÛ¼ºÇÏ¿© 6to4 ¸±·¹ÀÌ ¶ó¿ìÅÍ·Î Àü¼Û

(4) 6to4 ¸±·¹ÀÌ ¶ó¿ìÅÍ´Â IPv4 Çì´õ¸¦ Á¦°ÅÇÏ°í IPv6 ÆÐŶÀ» IPv6 native host·Î Àü¼Û

<!--[if !vml]-->



<!--[endif]-->

























3. What's the difference between 6to4 routers and 6to4 relay routers with the viewpoint of their functionalities?

(1) 6to4 router

6to4 ¶ó¿ìÅÍ´Â IPv6 site¿Í IPv4 ³×Æ®¿öÅ©ÀÇ border router·Î½á, ÀÌ·¯ÇÑ 6to4 encapsulation °úÁ¤ÀÌ 6to4¶ó¿ìÅÍ¿¡¼­ ¼öÇàµÈ´Ù. IPv4¿Í IPv6 ³×Æ®¿öÅ©¸¦ ¿¬°áÇϱâ À§ÇØ ÅͳθµÀ» ±¸¼ºÇÏ°í IPv4 ³×Æ®¿öÅ©¸¦ ÅëÇØ ¼ö½ÅÃø 6to4 ¶ó¿ìÅÍ È¤Àº 6to4 ¸±·¹ÀÌ ¶ó¿ìÅÍ·Î Àü¼ÛÇÏ´Â ¿ªÇÒÀ» ÇÑ´Ù.

(2) 6to4 relay router

6to4 relay router´Â 6to4 ³×Æ®¿öÅ©¿¡¼­ Àü´ÞµÈ µ¥ÀÌÅ͸¦ ´Ù¸¥ IPv6 ³×Æ®¿öÅ©·Î Àü´ÞÇÏ´Â ¿ªÇÒÀ» ÇÑ´Ù. Áï,6to4 ¶ó¿ìÅÍÀÌÁö¸¸, 6to4 ÁÖ¼Ò¿Í native IPv6 ÁÖ¼Ò »çÀÌ¿¡ ¶ó¿ìÆÃÀ» º¯È¯ÇÏ´Â °ÍÀ» Áö¿øÇϵµ·Ï ¼³Á¤µÇ¾îÀÖÀ¸¸ç,ÆÐŶÀ» decapsulate ÇÏ´Â °Í°ú Æ÷¿öµù ÇÏ´Â ¿ªÇÒÀ» ÇÑ´Ù.

<!--[if !supportEmptyParas]--> <!--[endif]-->

4. Attacks with Neighbor Discovery(ND) messages

(1) °ø°Ý ¹æ¹ý

6to4 ¶ó¿ìÅÍ¿¡°Ô ÀÖ¾î ´Ù¸¥ ¸ðµç 6to4 ¶ó¿ìÅ͵é°ú 6to4 relay routerµéÀº ¸µÅ© »ó¿¡ ÀÖ´Ù°í °£ÁÖ ÇϹǷÎ,6to4 ¶ó¿ìÅÍ´Â Áß¿äµµ¿¡ µû¸¥ ½Å·Ú°ü°è¸¦ Çü¼ºÇسõÁö ¾Ê´Â ÇÑ, IPv4 ³×Æ®¿öÅ© ³»¿¡ ÀÖ´Â ¾î¶² ³ëµå¿¡ ÀÇÇؼ­ NDmassage¸¦ ÀÌ¿ëÇÑ °ø°ÝÀ» ¹ÞÀ» ¼ö°¡ ÀÖ´Ù. ÀÌ °ø°ÝÀÇ Å¸°ÙÀº 6to4 pseudo-interfaceÀÌ¸ç º¸Åë °ø°ÝÀÚµéÀºlink-local ÁÖ¼Ò¸¦ ÀÌ¿ëÇÑ´Ù. ¿¹¸¦ µé¾î, °ø°ÝÀº route advertisement³ª neighboradvertisement ¸Þ½ÃÁö¸¦ ´Ù½Ã ¸¸µé¾î È¥¶õÇÑ »óȲÀ» ÀÏÀ¸Å°·Á ÇÒ °ÍÀÌ´Ù. 6to4 pseudo-interfaceµéÀºlink-layer ÁÖ¼Ò¸¦ °®Áö ¾Ê±â ¶§¹®¿¡ ¸ðµç °ø°ÝµéÀÌ ÀûÀýÇÑ °ÍÀº ¾Æ´Ï´Ù. ±×·¯³ª neighbor discovery°üÁ¡¿¡¼­ 6to4 ¶ó¿ìÅÍ´Â ÇϳªÀÇ ¶ó¿ìÅͳª È£½ºÆ®·Î ¿©°ÜÁú ¼ö ÀÖ´Ù.

(2) ´ëÀÀ ¹æ¹ý

1) ND ¸Þ½ÃÁöÀÇ »ç¿ëÀ» ±ÝÁö½ÃŲ´Ù. ÀÌ°ÍÀº link-local ¹üÀ§ÀÇ ÁÖ¼Ò¸¦ »ç¿ëÇÏ´Â ¸ðµç ÆÐŶµéÀ» Â÷´Ü ÇÒ °ÍÀ̶ó´Â °ÍÀ»ÀǹÌÇÑ´Ù. ±×·¯³ª ÀÌ ¹æ¹ýÀº ÇÔÁ¤ÀÌ ¼û¾î ÀÖ´Ù. ±× ÀÌÀ¯´Â ÀÌ°ÍÀº Á¤»óÀûÀÎ ND ¸Þ½ÃÁö¸¦ ±ÝÁö½ÃÅ°°Ô µÉ °ÍÀ̱⠶§¹®ÀÌ´Ù.

2) 6to4 pseudo-interface¸¦ ´Ù¸¥ ÀÎÅÍÆäÀ̽ºµé·ÎºÎÅÍ °í¸³½Ãų ¼ö ÀÖ´Ù.

3) ¸¸¾à ND ¸Þ½ÃÁö°¡ ÇÊ¿äÇÒ °æ¿ì, link-local ÁÖ¼Ò¸¦ »ç¿ëÇÏ¿© ¾ÈÀüÇÏ°Ô ÆÐŶÀ» ±³È¯Çϱâ À§Çؼ­ IPsecÀ̳ª È®ÀåµÈ SEND°¡ »ç¿ëµÉ ¼ö ÀÖ´Ù.

<!--[if !supportEmptyParas]--> <!--[endif]-->

5. Spoofing traffic to 6to4 nodes/native ipv6 nodes

(1) °ø°Ý ¹æ¹ý

6to4 ¶ó¿ìÅÍ´Â ipv4ÁÖ¼Ò¸¦ ¹ö¸®±â ¶§¹®¿¡ spoopingµÈ IPv6ÁÖ¼Ò¸¸ ¾Ë°Ô µÈ´Ù. µû¶ó¼­ Dos°ø°ÝÀ» À§ÇØIPv6ÁÖ¼Ò¸¦ spoofingÇؼ­ IPv6³ëµå·Î º¸³» IPv6³ëµå´Â ÇØ´ç ÁÖ¼Ò·Î ¸Þ½ÃÁö¸¦ º¸³»°Å³ª ÃßÀûÇÏ·Á Çصµ SpoofingµÈ ÁÖ¼Ò¸¸ ¾Ë°í Àֱ⠶§¹®¿¡ AttackÀ§Çè¿¡ ³ëÃâµÇ´Â °ÍÀÌ´Ù.

(2) ´ëÀÀ¹æ¾È

1) ´Ù¸¥ IPv6 ³×Æ®¿öÅ©¿¡¼­ µé¾î¿À´Â ÆÐŶÀ» °É·¯³½´Ù.

2) 6to4 relay´Â 6to4 ÁÖ¼Ò°¡ source ÁÖ¼Ò·Î µÇ¾îÀÖ´Â °æ¿ì drop ÇÑ´Ù.

<!--[if !supportEmptyParas]--> <!--[endif]-->

6. Reflecting traffic to 6to4 nodes/native ipv6 nodes

(1)°ø°Ý¹æ¹ý

IPv4 ¶Ç´Â native IPv6 ³×Æ®¿öÅ©ÀÇ °ø°ÝÀÚ°¡ 6to4³ëµåÀÇ ÁÖ¼Ò·Î ÀÚ½ÅÀÇ ÁÖ¼Ò¸¦ À§ÀåÇÏ¿© ´Ù¸¥ ³ëµåµé¿¡°Ô ¸Þ½ÃÁö¸¦Àü´ÞÇϸé ÀÌ¿¡ ´ëÇÑ ÀÀ´äÀÌ À§Àå ÁÖ¼Ò·Î º¸³»Áö°Ô µÈ´Ù. À§Àå¸Þ½ÃÁö¸¦ ºê·Îµåij½ºÆ® ¶Ç´Â ¸ÖƼij½ºÆ® ÇÏ´Â °æ¿ì À§ÀåÇÑ ÁÖ¼ÒÀÇ6to4³ëµå¿¡°Ô ¸¹Àº Æ®·¡ÇÈÀÌ ¹ß»ýÇÏ¿© DoS°ø°ÝÀÌ ÀÌ·ç¾îÁö°Ô µÈ´Ù.

(2) ´ëÀÀ¹æ¾È

1) relay router¿¡¼­ IPv4 source ÁÖ¼Ò°¡ ±×¿¡ »óÀÀÇÏ´Â IPv6 source ÁÖ¼Ò·Î spoofing µÇ¾ú´ÂÁö security check¸¦ ÇÏ¸é µÈ´Ù.

2) IPv4 service provider°¡ source IPv4 ÁÖ¼Ò¸¦ Á¶ÀÛ ¸øÇϵµ·Ï ingress filteringÀ» ÇÏ¸é µÈ´Ù.

3) IPv4 service provider°¡ source IPv6 ÁÖ¼Ò°¡ 6to4ÁÖ¼Ò·Î spoofingµÇ´Â °ÍÀ» ¸·±â À§ÇØ ingress filteringÀ» ÇÏ¸é µÈ´Ù.

<!--[if !supportEmptyParas]--> <!--[endif]-->

7. Local IPv4 broadcast attack

(1) °ø°Ý¹æ¹ý

Local IPv4 broadcast attacÀ̶õ 6to4³ëµå°¡ 6to4¶ó¿ìÅÍ¿¡°Ô ¶ó¿ìÅÍÀÇ ¼­ºê³Ý ºê·Îµå ij½ºÆ® ÁÖ¼ÒÀÇ ÆÐŶÀ»IPv4·Î ĸ½¶È­Çؼ­ Àü¼ÛÇÏ°Ô µÇ¸é 6to4¶ó¿ìÅÍ´Â ÇØ´ç ÆÐŶÀ» ¼­ºê³Ý¿¡ ºê·Îµå ij½ºÆ® ÇÔÀ¸·Î½á ¼­ºê³Ý Àüü¿¡ ´ëÇÑ DoS°ø°ÝÀ»¸»ÇÑ´Ù. ÀÌ °ø°ÝÀº 6to4 ¶ó¿ìÅÍ°¡ IPv4 ÆÐŶ¿¡ ĸ½¶È­µÈ IPv6ÁÖ¼Ò¸¦ üũÇÏ¿© ºê·ÎƮij½ºÆ® ÁÖ¼ÒÀ̰ųª ¸ÖƼij½ºÆ® ÁÖ¼Ò¸¦°É·¯³»Áö ¾ÊÀ» ¶§ Àû¿ëÇÒ ¼ö ÀÖ´Â °ø°Ý ¹æ¹ýÀÌ´Ù.

(2) ´ëÀÀ¹æ¹ý

ÀÌ °ø°Ý¿¡ ´ëÀÀÇϱâ À§Çؼ­´Â 6to4¶ó¿ìÅÍ¿¡¼­ ĸ½¶È­ µÈ ÆÐŶÀÇ ÁÖ¼Ò¸¦ È®ÀÎÇؼ­ ºê·Îµåij½ºÆ® ÁÖ¼ÒÀ̰ųª ¸ÖÅ×ij½ºÆ® ÁÖ¼ÒÀÏ °æ¿ì ÇÊÅ͸µ Çϸé ÇØ°áÇÒ ¼ö ÀÖ´Ù.

<!--[if !supportEmptyParas]--> <!--[endif]-->

8. Theft of service

(1) °ø°Ý¹æ¹ý

6to4 ¸±·¹ÀÌ ¶ó¿ìÅÍÀÇ °ü¸®ÀÚ°¡ Á¤Ã¥ÀûÀ¸·Î ƯÁ¤ 6to4 »çÀÌÆ® ¶Ç´Â IPv6»çÀÌÆ®¿¡ ´ëÇØ ¸±·¹ÀÌ ¼­ºñ½º¸¦ Á¦ÇÑÇÏ°í ½ÍÀº °æ¿ìÁ¦ÇÑÇÒ »çÀÌÆ®ÀÇ ¼­ºê³Ý ÁÖ¼ÒÀÇ ¶ó¿ìÆà Á¤º¸¸¦ Á¶ÀÛÇÔÀ¸·Î½á ¼­ºñ½º¸¦ Á¦ÇÑÇÑ´Ù. ±×·¯³ª ÀÌ·± Á¦ÇÑ¿¡µµ ºÒ±¸ÇÏ°í ¼­ºñ½º¸¦ »ç¿ëÇÒ ¼öÀִµ¥ ÀÌ·± »óȲÀ» Theft of Service¶ó°í ÇÑ´Ù. ¿¹¸¦ µé¾î 2002::/16 ¶Ç´Â 192.188.99.0/24ÀÇÁÖ¼Ò¸¦ Á¦ÇÑ ÇßÁö¸¸ »ç¿ëÀÚ°¡ ¼Ò½º ÁÖ¼Ò¸¦ ¸±·¹ÀÌÀÇ ÁÖ¼Ò(192.88.99.1)·Î º¸³»°Å³ª ¶ó¿ìÆà ÇØ´õ¿¡ ƯÁ¤ 6to4¶ó¿ìÅ͸¦ÁöÁ¤ÇÔÀ¸·Î½á Á¦ÇÑµÈ ¸±·¹ÀÌ ¶ó¿ìÅ͸¦ À§È¸Çؼ­ ÆÐŶ Àü¼Û ¼­ºñ½º¸¦ »ç¿ëÇÏ´Â °ÍÀÌ´Ù.

(2) ÇØ°á¹æ¹ý

ÀÌ À§Çù¿ä¼Ò¿¡ ´ëÇÑ ÇØ°áÃ¥À¸·Î´Â Àڽſ¡°Ô µµÂøÇÑ ÆÐŶÀÇ ¼Ò½º ÁÖ¼Ò°¡ ÀÚ½ÅÀÇ ÁÖ¼ÒÀÎÁö °Ë»çÇÏ´Â ¹æ¹ý, ¼­ºñ½º °ÅºÎ ¸®½ºÆ®°¡ ¾Æ´Ñ¼­ºñ½º Çã¿ë ¸®½ºÆ®¸¦ ¸¸µåµç ¹æ¹ý ±×¸®°í ¸±·¹ÀÌ ¶ó¿ìÅÍ°¡ Àڽſ¡°Ô ÅͳθµÀ» ÅëÇØ µµÂøÇÑ IPv6ÆÐŶÀÇ ¸ñÀûÁÖ¼Ò°¡ ÀÚ½ÅÀÌ ¾Æ´Ñ°æ¿ì °É·¯³»´Â ¹æ¹ýÀ¸·Î ÇØ°áÇÒ ¼ö ÀÖ´Ù.

<!--[if !supportEmptyParas]--> <!--[endif]-->

9. Relay operators seen as source of abuse

(1) °ø°Ý¹æ¹ý

6to4 relay¸¦ ÀÌ¿ëÇÏ¿© trafficÀ» À͸íÈ­ÇÑ´Ù. ÀÌ°ÍÀº packetÀÌ relay·ÎºÎÅÍ 6to4 site±îÁö ÅͳθµÀ̵ȴÙ. IPv4 source address´Â relay¸¦ ÀÌ¿ëÇÏ¿© "protocol-41" attackÀÇ source󷳺¸ÀÌ°ÔÇÏ¿© 6to4 relay service¿¡ Á¢¼ÓÀ» abuse¶ó°í »ý°¢Çϰųª Àüü IPv4 ÁÖ¼Ò ¹üÀ§¸¦ abuse³ªspamÀ¸·Î º¸°í °ÅÀý ¶Ç´Â "spammer databases"¾ÈÀÇ blacklist¿¡ ¿Ã¸®´Â º¸¾ÈÀ§ÇùÀÌ´Ù.

(2) ´ëÀÀ¹æ¹ý

1) 192.88.99.0/24¾ÈÀÇ 6to4 anycast address¸¦ source address·Î½á »ç¿ë

ÅÂ±× : 6to4, securityÆ÷½ºÆ® ¸ÞŸ Á¤º¸
ÀÚµ¿ °Ë»ö °ü·Ã±ÛIPv6by ±èÇö¹Î
4Àå ¿¹½Àby peril
Deilvery [¶ó¿ìÅÍ]Á÷Á¢Àü´Þ °£Á¢Àü´Þby ÇØÅäÀϵµ·ù
TCP/IP ´Ù¼¸¹ø° ÁÖ (09.03.31 È­¿äÀÏ)by Á¤ÇØ¿Õ
Packet Structure - µÎ¹ø° IP(Internet Protocol) by yOUNGRAP
Å°¿öµå °Ë»ö±ÛÄÄÅ͸¦ »õ·Î »ÌÀ¸´Ï.... from ÇÑÄÆ ¼Ó¿¡ »ì¾ÆÀÖ´Â ³¶¸¸°ú ±â¾ï
SM¹ö½º ÄÁÆ®·Ñ·¯, ´Ù¸¥ Çϳª´Â Microsoft 6to4 Adapter.. -_- Çؼ­!! ±¸±ÛÀ» µÚÁ³´Ù. ±×·¯´Ï µÎ°³ ´Ù ÇØ°áÃ¥ÀÌMicrosoft 6to4 Adapter. ÀÌ°Ô Á» °ñ¶§¸°µ¥.. ¾Æ¹«Æ° Àú°Ô IP v4¶û v6¶û °ü·ÃÀÌ ÀÖ´Ù´Â
[IPv6] WinXP IPv6 ¼³Á¤ from ¹Îµé·¹Ã³·³
infinite infinite fe80::2e0:91ff:fe0c:4a4f ÀÎÅÍÆäÀ̽º 3: 6to4 Tunneling Pseudo-Interface ÁÖ¼Ò Çü½Ä DAD »óÅ À¯È¿ ¼ö¸í Pref. ¼ö¸í ÁÖ¼Ò --------- ---------- ------------ ------------ ----------------------------- ±âŸ ±âº»
Network Programming for Microsoft Window ... from Sempre Avanti, Renaissance man
ISATAP(Intrasite Automatic Tunnel Addressing Protocol), 6to4, 6over4, IPv4 compatible, ÀÌ Áß6to4´Â IPv4 ¶ó¿ìÅÍ È¯°æÇÏ¿¡¼­ IPv6/IPv4 È£½ºÆ®µé°£ÀÇWindows XP¿¡¼­´Â 6to4 ¼­ºñ½º°¡ ÀÚµ¿À¸·Î ½ÃÀ۵ǵµ·Ï µÇ¾î ÀÖ´Ù.
IPv6 ¾îÇø®ÄÉÀ̼ÇÀº IPv4¿Í IPv6 ÁÖ¼Ò Áß ... from NeverStop
        2     6to4 IPv6 ÁÖ¼Ò::/96                                20      °ð ¾îÇø®ÄÉÀ̼ÇÀº native IPv6 ÁÖ¼Ò¿Í 6to4 IPv6 ÁÖ¼Ò°¡ ÀÖ´Â °æ¿ì, native IPv6 ÁÖ¼Ò·Î ¸ÕÀú Á¢¼Ó½ÃµµÇÏ°Ô µË´Ï´Ù.
IPv6·ÎÀÇ Àüȯ "³Ê¹« ´À¸®´Ù" from °³À﬽ÀÀåÀÔ´Ï´Ù
³ª¸ÓÁö ¼±ÅÃÀº 6Åõ4(6to4) ºÀÀÔÀ̶ó´Â °ÍÀ» »ç¿ëÇؼ­ IPv4 ȸ¼±¿¡¼­ IPv6 Æ®·¡ÇÈÀ» ÅͳθµÇÏ´Â °ÍÀÌ´Ù(µÎ °³ »ç¹«½Ç°£¿¡ ÀÎÅÍ³Ý »óÀÇ IPX Åͳθµ°ú À¯»çÇÑ ¹æ½ÄÀ¸·Î).°¡Àå °£´ÜÇÑ 6Åõ4 ¹æ¾ÈÀº


  ÃßõÇÏ±â   ¸ñ·Ïº¸±â

Copyright 1999-2024 Zeroboard / skin by zero