Baker, F., Li, X., Bao, C., and Yin, K. (2011). Framework
for IPv4/IPv6 Translation. RFC 6144 (Informational).
Bao, C., Huitema, C., Bagnulo, M., Boucadair, M., and Li,
X. (2010). IPv6 Addressing of IPv4/IPv6 Translators.
RFC 6052 (Proposed Standard).
Bao, C., Li, X., Zhai, Y., and Shang, W. (2014). dIVI: Dual-
Stateless IPv4/IPv6 Translation. draft-xli-behave-
divi-06.
Bellovin, S. M. (1989). Security problems in the tcp/ip
protocol suite. SIGCOMM Comput. Commun. Rev.,
19(2):32–48.
Conta, A. and Gupta, M. (2006). Internet control message
protocol (icmpv6) for the internet protocol version 6
(ipv6) specification. RFC 4443 (Proposed standard).
Convery, S. and Miller, D. (2004). Ipv6 and ipv4 threat
comparison and best-practice evaluation.
Davies, E., Krishnan, S., and Savola, P. (2007).
IPv6 Transition/Co-existence Security Considera-
tions. RFC 4942 (Informational).
Durand, A., Droms, R., Woodyatt, J., and Lee, Y. (2011).
Dual-Stack Lite Broadband Deployments Following
IPv4 Exhaustion. RFC 6333 (Proposed Standard).
Garg, A. and Reddy, A. N. (2004). Mitigation of dos at-
tacks through qos regulation. Microprocessors and
Microsystems, 28(10):521–530.
Gervais, A. (2012). Security analysis of industrial control
systems. Aalto University-KTH Stockholm, Jun, 29.
Gont, F. (2011). Security assessment of the internet protocol
version 4. RFC 6274 (Informational).
Gupta, M. and Melam, N. (2006). Authentica-
tion/Confidentiality for OSPFv3. RFC 4552 (Pro-
posed Standard).
Harris, B. and Hunt, R. (1999). Tcp/ip security threats
and attack methods. Computer Communications,
22(10):885–897.
Hernan, S., Lambert, S., Ostwald, T., and Shostack, A.
(2006). Threat modeling-uncover security design
flaws using the stride approach. MSDN Magazine-
Louisville, pages 68–75.
Huston, G. (2015). IPv4 Address Report.
ITU-T (2013). ITU-T Rec. X.1037 (10/2013) IPv6 techni-
cal security guidelines. Recommendation X.1037.
Khallouf, Z., Roca, V., Moignard, R., and Loye, S. (2005).
A Filtering Approach for an IGMP Flooding Resilient
Infrastrcuture. 4th Conference on Security and Net-
work Architectures(SAR’05), Batz sur Mer, France.
Li, X., Bao, C., and Baker, F. (2011a). IP/ICMP Translation
Algorithm. RFC 6145 (Proposed Standard). Updated
by RFC 6791.
Li, X., Bao, C., Chen, M., Zhang, H., and Wu, J. (2011b).
The China Education and Research Network (CER-
NET) IVI Translation Design and Deployment for the
IPv4/IPv6 Coexistence and Transition. RFC 6219 (In-
formational).
Li, X., Bao, C., Dec, W., Troan, O., , Matsushima, S., Mu-
rakami, T., and Taylor, T. (2015). Mapping of Address
and Port using Translation (MAP-T). RFC 7599 (Pro-
posed Standard).
Low, C. (2001). Icmp attacks illustrated. SANS Institute
URL: http://rr. sans. org/threats/ICMP attacks. php
(12/11/2001).
Matsuhira, N. (2015). SA46T Address Translator. draft-
matsuhira-sa46t-at-05.
Mawatari, M., Kawashima, M., and Byrne, C. (2013).
464XLAT: Combination of Stateful and Stateless
Translation. RFC 6877.
McRee, R. (2009). IT Infrastructure Threat Modeling
Guide. Microsoft Technet.
Moy, J. (1998). OSPF Version 2. RFC 2328 (INTERNET
STANDARD). Updated by RFCs 5709, 6549, 6845,
6860.
Nikander, P., Kempf, J., and Nordmark, E. (2004). IPv6
Neighbor Discovery (ND) Trust Models and Threats.
RFC 3756 (Informational).
Nordmark, E. and Gilligan, R. (2005). Basic Transition
Mechanisms for IPv6 Hosts and Routers. RFC 4213
(Proposed Standard).
NRO (2014). Free Pool of IPv4 Address Space Depleted
[Online]. Available: http://www.nro.net/news/ipv4-
free-pool-depleted.
OWASP (2015). Application Threat Modeling. OWASP
Foundation.
Pilihanto, A. (2011). A complete guide on ipv6 attack and
defense. Sans. org [online].
Rouiller, S. A. (2003). Virtual lan security: weaknesses and
countermeasures. available at uploads. askapache.
com/2006/12/vlan-security-3. pdf.
Troan, O., Dec, W., Li, X., Bao, C., Matsushima, S., Mu-
rakami, T., and Taylor, T. (2015). Mapping of Address
and Port with Encapsulation (MAP-E). RFC 7597
(Proposed Standard).
Tsou, T., Cui, Y., Boucadair, M., Farrer, I., and Lee, Y.
(2015). Lightweight 4over6: An Extension to the
Dual-Stack Lite Architecture. RFC 7596 (Proposed
Standard).
APPENDIX
Table 4: ThreatID Codes.
Basic IPv6 transition technologies
IP/ICMP Translation Algorithm RFC6145 IP/ICMP
Encapsulation of
IPv6 in IPv4
RFC4213 4encaps
Generic IPv6 transition technologies
Dual Stack - DS
Single Translation - 1transl
Double Translation - 2transl
Encapsulation - encaps
The STRIDE Towards IPv6: A Comprehensive Threat Model for IPv6 Transition Technologies
251