Overview of IPv6 Based DDoS and DoS Attacks Detection Mechanisms

被引:7
|
作者
Bahashwan, Abdullah Ahmed [1 ]
Anbar, Mohammed [1 ]
Hanshi, Sabri M. [2 ]
机构
[1] Univ Sains Malaysia USM, Natl Adv IPv6 Ctr NAv6, Gelugor 11800, Penang, Malaysia
[2] Seiyun Community Coll, Hadhramaut, Yemen
来源
关键词
IPv6; ICMPv6; NDP; ICMPv6 based DDoS & DoS utilization; IDS; FRAMEWORK; SYSTEM;
D O I
10.1007/978-981-15-2693-0_11
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In recent years, the number of Internet users and devices are rapidly increased. For this reason, the Internet Assigned Number Authority (IANA) launched a new protocol called Internet Protocol version six (IPv6) next generation. The IPv6 provides new features that fit the internet revolution. IPv6 is equipped with new protocols such as Neighbor Discovery Protocol (NDP) and Internet Control Messages protocol version six (ICMPv6). In fact, ICMPv6 is considered as the backbone of the IPv6 protocol since it is responsible for many key functions like the NDP process. In addition, the NDP protocol is a stateless protocol that gives the lack of authentication to NDP messages, which is vulnerable to many types of attacks such as Distributed Denial of Services (DDoS) and Denial of Services (DoS) flooding attacks. In this type of attacks, the attacker sends an enormous volume of abnormal traffic to increase network congestion and break down the network. Under those circumstances, the first line of defense in a network has been supplemented by additional devices and tools that supervise the network activities and monitor the network traffic behaviors as well as to stop unauthorized intrusions. Overall, the aim of this review paper is to give pure thoughts about the IPv6 features and the most important related protocols like ICMPv6 protocol and NDP protocol. Also, this article discusses DDoS and DoS attack based on ICMPv6 protocol. Likewise, this article gives a comprehensive review of the IPv6 Intrusion Detection Systems based on DDoS & DoS attacks with their features and security limitations.
引用
收藏
页码:153 / 167
页数:15
相关论文
共 50 条
  • [41] Stack Overflow Based Defense for IPv6 Router Advertisement Flooding (DoS) Attack
    Goel, Jai Narayan
    Mehtre, B. M.
    PROCEEDINGS OF 3RD INTERNATIONAL CONFERENCE ON ADVANCED COMPUTING, NETWORKING AND INFORMATICS, ICACNI 2015, VOL 2, 2016, 44 : 299 - 308
  • [42] An Overview of IPv4 to IPv6 Transition and Security Issues
    Sabir, Muhammad Rizwan
    Fahiem, Muhammad Abuzar
    Mian, Muhammad Saleem
    2009 WRI INTERNATIONAL CONFERENCE ON COMMUNICATIONS AND MOBILE COMPUTING: CMC 2009, VOL 3, 2009, : 636 - +
  • [43] An Overview on Detection and Prevention of Application Layer DDoS Attacks
    Black, Samuel
    Kim, Yoohwan
    2022 IEEE 12TH ANNUAL COMPUTING AND COMMUNICATION WORKSHOP AND CONFERENCE (CCWC), 2022, : 791 - 800
  • [44] Detection of DoS and DDoS Attacks in NGMN Using Frequency Domain Analysis
    Hashim, Fazirulhisyam
    Kibria, M. Rubaiyat
    Jamalipour, Abbas
    2008 14TH ASIA-PACIFIC CONFERENCE ON COMMUNICATIONS, (APCC), VOLS 1 AND 2, 2008, : 547 - 551
  • [45] A Proposed Technique to Detect DDoS Attack on IPv6 Web Applications
    Aleesa, Ahmed Marwan
    Hassan, Rosilah
    2016 FOURTH INTERNATIONAL CONFERENCE ON PARALLEL, DISTRIBUTED AND GRID COMPUTING (PDGC), 2016, : 118 - 121
  • [46] A Study of DDoS Reflection Attack on Internet of Things in IPv4/IPv6 Networks
    Simon, Marek
    Huraj, Ladislav
    SOFTWARE ENGINEERING METHODS IN INTELLIGENT ALGORITHMS, VOL 1, 2019, 984 : 109 - 118
  • [47] An empirical analysis of IPv6 transition mechanisms
    Shin, MK
    Kim, HJ
    Santay, D
    Montgomery, D
    8TH INTERNATIONAL CONFERENCE ON ADVANCED COMMUNICATION TECHNOLOGY, VOLS 1-3: TOWARD THE ERA OF UBIQUITOUS NETWORKS AND SOCIETIES, 2006, : U1991 - U1996
  • [48] NSIS-based Firewall Detection in Mobile IPv6
    Li Xin
    ICN 2008: SEVENTH INTERNATIONAL CONFERENCE ON NETWORKING, PROCEEDINGS, 2008, : 698 - 702
  • [49] Detection and Mitigation of DoS and DDoS Attacks in IoT-Based Stateful SDN: An Experimental Approach
    Galeano-Brajones, Jesus
    Carmona-Murillo, Javier
    Valenzuela-Valdes, Juan F.
    Luna-Valero, Francisco
    SENSORS, 2020, 20 (03)
  • [50] A FPGA-based intrusion detection system in IPv6
    Bin, He
    Fushan, Wei
    2007 INTERNATIONAL SYMPOSIUM ON COMPUTER SCIENCE & TECHNOLOGY, PROCEEDINGS, 2007, : 877 - 881