<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.ietf-opsec-ipv6-host-scanning" target="https://datatracker.ietf.org/doc/html/draft-ietf-opsec-ipv6-host-scanning-08">
   <front>
      <title>Network Reconnaissance in IPv6 Networks</title>
      <author initials="F." surname="Gont" fullname="Fernando Gont">
         <organization>Huawei Technologies</organization>
      </author>
      <author initials="T." surname="Chown" fullname="Tim Chown">
         <organization>Jisc</organization>
      </author>
      <date month="August" day="28" year="2015" />
      <abstract>
	 <t>IPv6 offers a much larger address space than that of its IPv4 counterpart.  An IPv6 subnet of size /64 can (in theory) accommodate approximately 1.844 * 10^19 hosts, thus resulting in a much lower host density (#hosts/#addresses) than is typical in IPv4 networks, where a site typically has 65,000 or fewer unique addresses.  As a result, it is widely assumed that it would take a tremendous effort to perform address-scanning attacks against IPv6 networks; therefore, IPv6 address-scanning attacks have been considered unfeasible.  This document formally obsoletes RFC 5157, which first discussed this assumption, by providing further analysis on how traditional address-scanning techniques apply to IPv6 networks and exploring some additional techniques that can be employed for IPv6 network reconnaissance.
	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-ietf-opsec-ipv6-host-scanning-08" />
   
</reference>
