Improved Mechanism to Prevent Denial of Service Attack in IPv6 Duplicate Address Detection Process
نویسندگان
چکیده
From the days of ARPANET, with slightly over two hundred connected hosts involving five organizations to a massive global, always-on network connecting hosts in the billions, the Internet has become as important as the need for electricity and water. Internet Protocol version 4 (IPv4) could not sustain the growth of the Internet. In ensuring the growth is not stunted, a new protocol, i.e. Internet Protocol version 6 (IPv6) was introduced that resolves the addressing issue IPv4 had. In addition, IPv6 was also laden with new features and capabilities. One of them being address auto-configuration. This feature allows hosts to self-configure without the need for additional services. Nevertheless, the design of IPv6 has led to several security shortcomings. Duplicate Address Detection (DAD) process required for auto-configuration is prone to Denial of Service (DoS) attack in which hosts are unable to configure themselves to join the network. Various mechanisms, SeND, SSAS, and the most recent being Trust-ND, have been introduced to address this issue. Although these mechanisms were able to circumvent DoS attack on DAD process, they have introduced various side effects, i.e. complexities and degradation of performance. This paper reviews the shortcomings of these mechanism and proposes a new mechanism, Secure-DAD, that addresses them. The performance comparison between Trust-ND and Secure-ND also showed that Secure-DAD is more promising with improvement in terms of processing time reduction of 45.1% compared to Trust-ND while preventing DoS attack in IPv6 DAD process. Keywords—Secure-DAD; Duplicate Address Detection; Denial of Service Attack; IPv6 Security; Address auto-configuration
منابع مشابه
Denial of Service Attack in IPv6 Duplicate Address Detection Process
IPv6 was designed to replace the existing Internet Protocol, that is, IPv4. The main advantage of IPv6 over IPv4 is the vastness of address space. In addition, various improvements were brought to IPv6 to address the drawbacks in IPv4. Nevertheless, as with any new technology, IPv6 suffers from various security vulnerabilities. One of the vulnerabilities discovered allows Denial of Service Atta...
متن کاملAvoiding DAD for Improving Real-Time Communication in MIPv6 Environments
Current specification of address configuration mandates the execution of the Duplicate Address Detection (DAD) mechanism to prevent address duplication. However, a proper support for real time multimedia applications in mobile IPv6 nodes is undermined by the disruption imposed by DAD. In order to overcome this limitation, the usage of randomly generated IPv6 Interface Identifiers without previo...
متن کاملSmart Buffering for seamless handover in Proxy Mobile IPv6
ProxyMobile IPv6 (PMIPv6) is proposed as a new network-based mobility protocol and it does not require MN’s involving in mobility management. MN can handover relatively faster in PMIPv6 than in Mobile IPv6 (MIPv6) because it actively uses link-layer attachment information and reduces themovement detection time, and eliminates duplicate address detection procedure. However, the current PMIPv6 ca...
متن کاملF-STONE: A Fast Real-Time DDOS Attack Detection Method Using an Improved Historical Memory Management
Distributed Denial of Service (DDoS) is a common attack in recent years that can deplete the bandwidth of victim nodes by flooding packets. Based on the type and quantity of traffic used for the attack and the exploited vulnerability of the target, DDoS attacks are grouped into three categories as Volumetric attacks, Protocol attacks and Application attacks. The volumetric attack, which the pro...
متن کاملAn Approach to Reliable and Efficient Routing Scheme for TCP Performance Enhancement in Mobile IPv6 Networks
In Mobile IPv6, the handover process reveals numerous problems manifested by movement detection, non-optimized time sequencing of handover procedures, latency in configuring a new care of address and binding update to a home agent (HA). These problems may cause packet loss as well as packet disruption. To mitigate such effects, Fast handover for Mobile IPv6 (FMIPv6) has been developed. FMIPv6 c...
متن کامل