Praktické testování nástrojů v IPv6 sítích
Loading...
Date
Authors
Advisor
Referee
Mark
A
Journal Title
Journal ISSN
Volume Title
Publisher
Vysoké učení technické v Brně. Fakulta elektrotechniky a komunikačních technologií
ORCID
Abstract
Táto bakalárska práca sa zaoberá praktickým testovaním existujúcich nástrojov určených na prieskum a bezpečnostné testovanie sietí v prostredí protokolu IPv6. Testované sú dva nástroje: Ptnetinspector, zameraný na detekciu zariadení v lokálnej sieti prostredníctvom mechanizmov ICMPv6 a Neighbor Discovery, a Penvuhu6, špecializovaný na fuzzing rozširujúcich hlavičiek IPv6. Hlavným výstupom práce je návrh komparatívnej metodiky merania, ktorá porovnáva správanie nezabezpečenej siete so stavom po aplikovaní cielených bezpečnostných politík. Merania prebehli na smerovačoch alebo prepínačoch Cisco, Turris Omnia a MikroTik, a to vo virtuálnom prostredí GNS3 aj na reálnom hardvéri. Výsledky odhalili konkrétne nedostatky testovaných nástrojov, napríklad falošne pozitívne vyhodnotenie útoku RA Spoofing, ako aj obmedzenia smerovačov, ktoré bez podpory hĺbkovej inšpekcie paketov neposkytujú úplnú a zároveň selektívnu ochranu proti testovaným vektorom útoku.
This bachelor's thesis deals with the practical testing of existing tools designed for the reconnaissance and security testing of networks using the IPv6 protocol. Two tools are tested: Ptnetinspector, which focuses on device detection within a local network through ICMPv6 and Neighbor Discovery mechanisms, and Penvuhu6, which specializes in fuzzing IPv6 extension headers. The main contribution of the thesis is the design of a comparative measurement methodology that compares the behavior of an unsecured network with its state after applying targeted security policies. The measurements were carried out on Cisco, Turris Omnia and MikroTik routers or switches, both in the virtual GNS3 environment and on real hardware. The results revealed specific shortcomings of the tested tools, such as a false-positive evaluation of an RA Spoofing attack, as well as limitations of the routers, which—without deep packet inspection support—do not provide complete and at the same time selective protection against the tested attack vectors.
This bachelor's thesis deals with the practical testing of existing tools designed for the reconnaissance and security testing of networks using the IPv6 protocol. Two tools are tested: Ptnetinspector, which focuses on device detection within a local network through ICMPv6 and Neighbor Discovery mechanisms, and Penvuhu6, which specializes in fuzzing IPv6 extension headers. The main contribution of the thesis is the design of a comparative measurement methodology that compares the behavior of an unsecured network with its state after applying targeted security policies. The measurements were carried out on Cisco, Turris Omnia and MikroTik routers or switches, both in the virtual GNS3 environment and on real hardware. The results revealed specific shortcomings of the tested tools, such as a false-positive evaluation of an RA Spoofing attack, as well as limitations of the routers, which—without deep packet inspection support—do not provide complete and at the same time selective protection against the tested attack vectors.
Description
Keywords
IPv6 , sieťová bezpečnosť , Ptnetinspector , Penvuhu6 , ICMPv6 , rozširujúce hlavičky , Neighbor Discovery , fuzzing , RA Spoofing , MikroTik , Turris Omnia , GNS3 , IPv6 , network security , Ptnetinspector , Penvuhu6 , ICMPv6 , extension headers , Neighbor Discovery , fuzzing , RA Spoofing , MikroTik , Turris Omnia , GNS3
Citation
BAČA, Ľ. Praktické testování nástrojů v IPv6 sítích [online]. Brno: Vysoké učení technické v Brně. Fakulta elektrotechniky a komunikačních technologií. 2026.
Document type
Document version
Date of access to the full text
Language of document
sk
Study field
bez specializace
Comittee
doc. Ing. Jan Jeřábek, Ph.D. (předseda)
doc. Ing. Ivo Lattenberg, Ph.D. (místopředseda)
Mgr. Martin Erlebach (člen)
Ing. Eva Holasová, Ph.D. (člen)
Ing. Petr Ilgner, Ph.D. (člen)
Ing. Kryštof Zeman, Ph.D. (člen)
Ing. Martin Rusz, Ph.D. (člen)
Date of acceptance
2026-06-16
Defence
Student prezentoval výsledky své práce a komise byla seznámena s posudky.
Student obhájil bakalářskou práci a odpověděl na otázky členů komise a oponenta.
Otázky:
1) Zjistil jste, že filtrování paketů s Destination Options hlavičkou pomocí ACL na zařízeních Cisco IOS-XE je nefunkční. Máte hypotézu, zda se jedná o dokumentovanou limitaci platformy, nebo o chybu implementace? Zkoušel jste ověřit chování na jiné verzi IOS-XE?
2) Identifikoval jste, že nástroj Ptnetinspector hlásí zranitelnost RA Guard i na správně nakonfigurovaných zařízeních. Jak by podle vás měl být nástroj upraven, aby tento falešně pozitivní výsledek eliminoval?
3) Všechna testování nástrojem Penvuhu6 na zařízení MikroTik probíhala výhradně ve virtuálním prostředí GNS3, zatímco Cisco a Turris byly testovány na reálném hardwaru. Z jakého důvodu nebyl MikroTik testován fyzicky a jak tato skutečnost podle vás ovlivňuje srovnatelnost výsledků?
Result of defence
práce byla úspěšně obhájena
