There are still very few tools to defend against IPv6 related attacks. To improve this situation I wrote a plugin for Snort, the popular open source intrusion detection system. This plugin adds detection rules and a preprocessor for the Neighbor Discovery Protocol.
It is aimed at the detection of suspicious activity in local IPv6 networks and can detect misconfigured network elements, as well as malicious activities from attackers on the network.
Martin Schütte is a system administrator and contributor to different open source projects. He studied political science and computing science in Potsdam.
He is currently working as a consultant for DECK36 in Hamburg.