Using multi-address generation and duplicate address detection to prevent DoS in IPv6

被引:8
|
作者
Song Guangjia [1 ]
Wang Hui [2 ]
Wang Hangjun [1 ]
机构
[1] Zhejiang A&F Univ, Sch Engn & Technol, Jiyang Coll, Zhuji, Peoples R China
[2] Natl Comp Network Emergency Response Tech Team Co, Beijing, Peoples R China
关键词
cryptography; computer network security; access protocols; IP networks; authorisation; multiaddress generation; duplicate address detection; Neighbour Discovery Protocol; Address Resolution Protocol; Internet Protocol address configuration; IP address; medium access control address; DAD; malicious node attacks; MAGD multiple address configuration; DoS prevention; IPv6;
D O I
10.1049/iet-com.2018.5686
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
The Neighbour Discovery Protocol and the Address Resolution Protocol are important protocols in the data link layer. Their functions include Internet Protocol (IP) address configuration, resolving the correspondence between an IP address and a medium access control address, and duplicate address detection (DAD). In DAD, the new address that the node is going to use is public, and thus, it is vulnerable to malicious node attacks. Moreover, address configuration is inefficient because only one address is generated and detected each time. In this study, the authors propose a multi-address generation and DAD scheme called MAGD. MAGD generates a set of addresses each time, but only discloses a part of the set during DAD, thereby reducing the risk of being attacked. DAD will only fail when all the addresses are in conflict, and thus, the efficiency of node's address configuration is enhanced. Experiments show that the additional overhead in the CPU and memory caused by MAGD's multiple address configuration is within an acceptable range. When subjected to denial-of-service (DoS) attacks, MAGD performs better than traditional encryption schemes.
引用
收藏
页码:1390 / 1396
页数:7
相关论文
共 50 条
  • [1] Novel Mechanism to Prevent Denial of Service (DoS) Attacks in IPv6 Duplicate Address Detection Process
    Ul Rehman, Shafiq
    Manickam, Selvakumar
    INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2016, 10 (04): : 143 - 153
  • [2] Fast duplicate address detection for Mobile IPv6
    Pongpaibool, Panita
    Sotthivirat, Pahol
    Kitisin, Sukumal I.
    Srisathapornphat, Chavalit
    2007 15TH IEEE INTERNATIONAL CONFERENCE ON NETWORKS, 2007, : 300 - +
  • [3] A Pull Model IPv6 Duplicate Address Detection
    Yao, Guang
    Bi, Jun
    Wang, Sen
    Zhang, Yueran
    Li, Yitian
    IEEE LOCAL COMPUTER NETWORK CONFERENCE, 2010, : 372 - 375
  • [4] Duplicate Address Detection Table in IPv6 Mobile Networks
    Alisherov, Farkhod
    Kim, Taihoon
    ADVANCED COMMUNICATION AND NETWORKING, 2010, 77 : 109 - 115
  • [5] Fast and Robust Duplicate Address Detection for Mobile IPv6
    Sotthivirat, Pahol
    Pongpaibool, Panita
    Kitisin, Sukumal
    Srisathapornphat, Chavalit
    2008 8TH INTERNATIONAL CONFERENCE ON ITS TELECOMMUNICATIONS, PROCEEDINGS, 2008, : 216 - +
  • [6] IPv6 Addressing Scheme with a Secured Duplicate Address Detection
    Kumar, Gyanendra
    Tomar, Parul
    IETE JOURNAL OF RESEARCH, 2022, 68 (05) : 3371 - 3378
  • [7] Building IPv6 addressing scheme using Hybrid Duplicate Address Detection to prevent Denial of Service Attack
    Gankotiya, Anil
    Kumar, Vishal
    Vaisla, Kunwar Singh
    COMPUTERS & ELECTRICAL ENGINEERING, 2024, 117
  • [8] Denial of Service Attack in IPv6 Duplicate Address Detection Process An Impact Analysis on IPv6 Address Auto-configuration Mechanism
    Rehman, Shafiq Ul
    Manickam, Selvakumar
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2016, 7 (06) : 232 - 238
  • [9] Integrated Framework to Detect and Mitigate Denial of Service (DoS) Attacks on Duplicate Address Detection Process in IPv6 Link Local Communication
    Rehman, Shafiq Ul
    Manickam, Selvakumar
    INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2015, 9 (11): : 77 - 86
  • [10] Remote Stateful Autoconfiguration for Mobile IPv6 Nodes with Server Side Duplicate Address Detection
    Mrugalski, Tomasz
    Wozniak, Jozef
    Nowicki, Krzysztof
    2010 AUSTRALASIAN TELECOMMUNICATION NETWORKS AND APPLICATIONS CONFERENCE (ATNAC), 2010,