| When the network security becomes more and more important to all kinds of people,the technology of firewall and IDS(Intrusion Detection System) have been more and more widely studied and applied. IDS can remedy the shortcoming of the firewall,that is, it can detect the intrusion behavior from the network with less expensive cost and adopt the protective method at the beginning of the intrusion. In a word, the intrusion detection is a kind of very important security technology of network.As the next generation of Internet Protocol, IPv6 not only can perfectly solve the problem that IP address will be exhausted very fast, but also is stronger and more eficient than IPv4 on such a lot of performance as the management, controls, network security, etc.. But it is still in the experimental phase now. Therefore, it is very meaningful to develop the intrusiond etection system under IPv6 environment now.The theme of this thesis is the new-type intrusion detection technique under IPv6 environment. It discusses emphatically how to detect various kinds of network intrusion under the environment that IPv4/IPv6 coexists. This thesis is mainly involved in three parts:The module of protocol analysis engine supporting both IPv4 and IPv6.The module of pre-processor of detection engine.The module of the scan detection based on the attacks of IPv6 loopholes.The module of detection engine.Firstly, This thesis introduces source, background and domestic and international current situation of the project in the part of the foreword.Secondly, this thesis introduces IPv6 protocol and IDS also. Thirdly,based on the above technical background,this thesis launches the discussion about the demand analysis and the detailed design of the modules mentioned above. Among them the more characteristic one is the design of the protocol analysis engine and the scan detection based on the attacks of IPv6 loopholes. This paper will discuss two solutions for enchancing the IDS performance,including load balance policies and analysis engine optimizations... |