ipv6 and attacks?
A security article on scam and cyberfraud stated:
Companies such as McAfee, of course, are on the front lines in the fight against organized cyber crime. CEO and president Dave DeWalt outlined the latest trends for eChannel Line and other sites and publications last month. The company sees an “alarming” increase in the amount and sophistication of malware and says there have been increasingly sophisticated attacks on government departments and corporations. He said these targets are beginning to tackle cyber security in the same way they traditionally protect physical assets. The emergence of IPv6, DeWalt said, is worrisome because its sophistication creates more more vulnerabilities
What exactly are these IPv6 vulnerabilities that DeWalt is referring to? And furthermore how are these attacks more sophisticated than the plethora of IPv4 attacks (packet modification, cross site scripting, buffer overflow, etc) that continue to increase in sophistication? When it comes to IPv6 there are some concerns however given the number of hosts connected today I would argue that the number of attacks in relation to the number of machines on the ipv6 networks is still quite low. Attacks are generally directed at applications, either on servers or clients, and the number of active ipv6 applications is quite low. The most blatant issue that will affect security in organizations is the use of tunnels (regardless of IPv4 or IPv6) because the security perimeter will be loosely compromised by the use of this tunnel originating on a client workstation or local router and the fact that this now bridges another domain to this domain.
Originally published on truman.net. See the archived copy.