IPv6 and security from a user’s point of viewAWT.beir. Zaccone Carmelo                                 Expert within the ‘Pôle Veille Technologique et Juridique’ Agence Wallonne des Télécommunications
AgendaQuick overview of network security considerationsThe AWT.be’ safe/secure IPv6 deployement scenarioConclusions: the errors, mistakes and lessons learned
Putting the rumorasideIt’s very often said that IPv6 is more secure than IPv4. This is a false rumour!IPsec is indeed mandatory but only mean a more secure data transport:
iif endorsed by all hosts
iif implemented by all applications
iif a key exchange system is adopted worldwidePutting the rumorasideAssuming all of this would however enable to have a more secure Internet: Operators may tracks sources of attacks because of
direct host-to-host communications
v6 infrastructure support peer-to-peer applicationsBoth protocols face most of the same threatsMostly the same:
Layer 3/Layer 4 spoofing/sniffing, network flooding,
DHCP vulnerabilities, Man in the Middle attacks,
Virus, spam, spit, ...
Nevertheless, IPv6 specificities bring new perspectives on some type of attacks
The IPv6 protocol security enhancements
closes doors for some threats
open new doors for some others threats
NDP & auto-configuration offers new attacks (e.g. fake RA, fake DaD reply). nb: SEND is a potential answer

Future Internet Week - IPv6 the way forward: IPv6 and security from a user’s point of view