기관회원 [로그인]
소속기관에서 받은 아이디, 비밀번호를 입력해 주세요.
개인회원 [로그인]

비회원 구매시 입력하신 핸드폰번호를 입력해 주세요.
본인 인증 후 구매내역을 확인하실 수 있습니다.

회원가입
서지반출
IPv6 호스트 접근제어를 위한 IPv6 주소관리서버의 설계 및 구현
[STEP1]서지반출 형식 선택
파일형식
@
서지도구
SNS
기타
[STEP2]서지반출 정보 선택
  • 제목
  • URL
돌아가기
확인
취소
  • IPv6 호스트 접근제어를 위한 IPv6 주소관리서버의 설계 및 구현
저자명
한선영,배상욱,김민순,손소라,손사민,Han. Sunyoung,Bae. Sangwook,Kim. Minsoon,Son. Sora,Sun. Shimin
간행물명
정보과학회논문지. Journal of KIISE. 정보통신
권/호정보
2014년|41권 1호|pp.13-21 (9 pages)
발행정보
한국정보과학회
파일정보
정기간행물|
PDF텍스트
주제분야
기타
이 논문은 한국과학기술정보연구원과 논문 연계를 통해 무료로 제공되는 원문입니다.
서지반출

기타언어초록

미래 인터넷은 지난 30년 동안 꾸준히 발전하여 온 인터넷 프로토콜이 2000년대에 이르러 사용자의 요구사항 증대, 통신환경의 급격한 변화 등으로 수용할 수 없게 되자 시작된 연구이다. 이는 기존의 인터넷 프로토콜 자체의 근본적인 문제를 해결하고자 하였으며, 2가지의 내용으로 진행되고 있다. 첫번째는 기존의 인터넷 프로토콜이 아닌 새로운 고유 식별자를 이용하여 사용한다는 것과 두번째는 기존의 인터넷 프로토콜을 개선하여 이용하고자 하는 내용이다. IPv6는 후자에 해당하는 내용으로 기존의 약 43억개의 주소를 할당할 수 있는 IPv4의 주소체계는 이미 한계에 도달하였으므로 이를 해결하고 기존의 QoS, Security 등의 다양한 문제를 해결하기 위해 개발된 것이다. IPv6는 IPv4에 비하여 다양한 특징이 있는데 이중에서 Stateless Auto Address Configuration (SLAAC)는 호스트가 스스로 주소를 생성하여 통신을 가능하게 하는 기능이다. 하지만 이와 같은 기능은 네트워크 관리자나 기업에서는 보안 및 관리측면에서 운영이 어렵다는 치명적인 단점을 가지고 있다. 이를 해결하기 위하여 중요한 호스트는 보호하며, 비인가 호스트의 접속을 차단하는 등의 호스트 제어 방법이 필요하다. 본 연구는 호스트 제어를 하기 위한 방법으로 ICMPv6 프로토콜을 이용하여 호스트의 주소 제어를 하도록 하였다. 먼저 호스트의 주소를 수집하는 과정은 Multicast Listener Discovery 프로토콜 및 Neighbor Discovery 프로토콜을 이용하였으며, 호스트 차단을 하기 위한 방법으로는 호스트들의 Neighbor Cache Table을 변조하는 방법을 이용하였다. 본 과정들을 이용하여 리눅스 환경에서 개발을 완료하였으며, 실제 연구망인 KOREN 네트워크 환경에서 테스트를 완료하였다.

기타언어초록

For the last 30 years, the Internet protocol has continuously evolved to meet the requirements of users, however, the rapid changes in communication environments in 2000s could not be accommodated appropriately. To overcome this situation, the research on the Future Internet has begun. To solve the fundamental limitations of the current Internet protocol, two research directions have been pursued. The first direction is to use a new unique identifier for host identification, which is totally different from the IP address in the current Internet protocol. The second direction is to continue to use IP addresses through the improvement of IP protocol by IP version 6 (IPv6). In the current situation that IPv4 addresses have been exhausted for 4.3 billion hosts, IPv6 addresses can be assigned to almost unlimited hosts in order to solve this IP address scarcity. Also, IPv6 has been designed and implemented to problems, such as Quality of Service (QoS) and Security. IPv6 is different from IPv4 in various features. Especially, Stateless Address Auto-Configuration (SLAAC) is a significant feature that allows an IPv6 host to generate and configure its own address for communications. However, this feature has drawbacks in terms of security in enterprise network management. To address this issue and protect sensitive hosts, a new host address management approach becomes required to block illegal host access to the enterprise network. In this study, we developed and implemented a mechanism collecting IPv6 addresses and blocking illegal hosts, based on Internet Control Message Protocol version 6 (ICMPv6), which is a companion protocol of IPv6. First, the method of collecting host addresses is explained to use Multicast Listener Discovery protocol that is the companion protocol of Neighbor Discovery protocol. Second, the method of blocking illegal hosts is described to use Neighbor Discovery protocol to manipulate Neighbor Cache Table for IPv6 host address management. For our test environment, a Linux system is used and our system was tested in the real research IPv6 network called KOREN.