earticle

논문검색

Novel Mechanism to Prevent Denial of Service (DoS) Attacks in IPv6 Duplicate Address Detection Process

초록

영어

Most IPv6 security issues are still the same as IPv4; IPv6 has its own unique design characteristics that have additional impact to system and network security, as well as the potential impact on policies and procedures. Address autoconfiguration is a key feature of the IPv6 protocol stack that allow hosts to generate own addresses using a confluence of information from other hosts and information from router advertisement. Duplicate Address Detection (DAD) is a process that is part of address autoconfiguration that is used to check if the addresses generated has already been configured. Nevertheless, the design of DAD process is vulnerable to Denial of Service (DoS) attack leaving hosts unconfigured. For example, any host can reply to Neighbor Solicitations (NS) for a temporary address, causing the other host to consider it as a duplicate and eventually reject the address. Various mechanisms such as SeND and SAVI has been introduced to address such attacks, but these techniques were not very effective as there were still possibilities of DoS attacks to be carried out. As such, a new mechanism is needed to more effectively prevent DoS attacks on DAD process. In this paper, we present a detailed design and development of a novel mechanism that can address the shortfalls of existing prevention techniques.

목차

Abstract
 1. Introduction
 2. Related Works
 3. Proposed Mechanism Approach
  3.1. Assumptions
  3.2. Threat Model 
  3.3. Design Goals
 4. Node Controller Model
  4.1. Node Controller Framework
  4.2. Components of Node Controller Model
 5. Message Authentication Model
  5.1. Secure Tag
  5.2. Secure Tag Format
 6. Secure Duplicate Address Detection Mechanism
 7. Conclusion and Future Work
 Acknowledgment
 References

저자정보

  • Shafiq Ul Rehman National Advanced IPv6 Centre (NAv6), Universiti Sains Malaysia
  • Selvakumar Manickam National Advanced IPv6 Centre (NAv6), Universiti Sains Malaysia

참고문헌

자료제공 : 네이버학술정보

    함께 이용한 논문

      ※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

      0개의 논문이 장바구니에 담겼습니다.