Risk assessment equation for IPv6 network / Athirah Rosli

Exposure to risk due to the implementation of IPv6 has made enterprise networks take immediate actions to avoid misrepresenting of risks and applying inadequate countermeasures. Being aware of the needs to calculate the risk of IPv6 threats and vulnerabilities, enterprises demand a proper equation t...

Full description

Saved in:
Bibliographic Details
Main Author: Rosli, Athirah
Format: Thesis
Language:English
Published: 2017
Subjects:
Online Access:https://ir.uitm.edu.my/id/eprint/37209/1/37209.pdf
Tags: Add Tag
No Tags, Be the first to tag this record!
id my-uitm-ir.37209
record_format uketd_dc
spelling my-uitm-ir.372092022-11-01T09:19:31Z Risk assessment equation for IPv6 network / Athirah Rosli 2017 Rosli, Athirah Computer networks. General works. Traffic monitoring TCP/IP (Computer network protocol) Exposure to risk due to the implementation of IPv6 has made enterprise networks take immediate actions to avoid misrepresenting of risks and applying inadequate countermeasures. Being aware of the needs to calculate the risk of IPv6 threats and vulnerabilities, enterprises demand a proper equation that is flexible to represent risks of the network. Unfortunately, the existing risk assessment equation is insufficient because it calculates risk per asset rather than the network as a whole. The current risk assessment equation also fails to relate security requirements with the dependencies of asset, threat and vulnerability. By using grounded theory, it is realized that confidentiality, integrity, and availability are important elements to be considered in risk assessment. Thus, this research proposes new risk assessment equation for IPv6 deployment that includes base score value that considers security goal of the network. The developed equation was validated via experimentation that involved testing the UDP flooding attack, TCP flooding attack and multicast attack by using OMNeT++. Result shows that the IRA6 equation is adequate in determining the risk value compared to the exvisting risk assessment equation. The risk values are associated into IPv6 threat model for future reference and as preliminary information for enterprise network. With the added information, it can be used by network administrators in their decision making and strategic planning for network security. Further research can include other elements in security goals which are nonrepudiation, authentication, authorization and accountability. 2017 Thesis https://ir.uitm.edu.my/id/eprint/37209/ https://ir.uitm.edu.my/id/eprint/37209/1/37209.pdf text en public masters Universiti Teknologi MARA (UiTM) Faculty of Computer and Mathematical Sciences Mat Taib, Abidah
institution Universiti Teknologi MARA
collection UiTM Institutional Repository
language English
advisor Mat Taib, Abidah
topic Computer networks
General works
Traffic monitoring
TCP/IP (Computer network protocol)
spellingShingle Computer networks
General works
Traffic monitoring
TCP/IP (Computer network protocol)
Rosli, Athirah
Risk assessment equation for IPv6 network / Athirah Rosli
description Exposure to risk due to the implementation of IPv6 has made enterprise networks take immediate actions to avoid misrepresenting of risks and applying inadequate countermeasures. Being aware of the needs to calculate the risk of IPv6 threats and vulnerabilities, enterprises demand a proper equation that is flexible to represent risks of the network. Unfortunately, the existing risk assessment equation is insufficient because it calculates risk per asset rather than the network as a whole. The current risk assessment equation also fails to relate security requirements with the dependencies of asset, threat and vulnerability. By using grounded theory, it is realized that confidentiality, integrity, and availability are important elements to be considered in risk assessment. Thus, this research proposes new risk assessment equation for IPv6 deployment that includes base score value that considers security goal of the network. The developed equation was validated via experimentation that involved testing the UDP flooding attack, TCP flooding attack and multicast attack by using OMNeT++. Result shows that the IRA6 equation is adequate in determining the risk value compared to the exvisting risk assessment equation. The risk values are associated into IPv6 threat model for future reference and as preliminary information for enterprise network. With the added information, it can be used by network administrators in their decision making and strategic planning for network security. Further research can include other elements in security goals which are nonrepudiation, authentication, authorization and accountability.
format Thesis
qualification_level Master's degree
author Rosli, Athirah
author_facet Rosli, Athirah
author_sort Rosli, Athirah
title Risk assessment equation for IPv6 network / Athirah Rosli
title_short Risk assessment equation for IPv6 network / Athirah Rosli
title_full Risk assessment equation for IPv6 network / Athirah Rosli
title_fullStr Risk assessment equation for IPv6 network / Athirah Rosli
title_full_unstemmed Risk assessment equation for IPv6 network / Athirah Rosli
title_sort risk assessment equation for ipv6 network / athirah rosli
granting_institution Universiti Teknologi MARA (UiTM)
granting_department Faculty of Computer and Mathematical Sciences
publishDate 2017
url https://ir.uitm.edu.my/id/eprint/37209/1/37209.pdf
_version_ 1783734401685782528