Optimized Duplicate Address Detection for the Prevention of Denial-of-Service Attacks in IPv6 Network

被引:3
作者
Pragya [1 ]
Kumar, Bijendra [1 ]
Kumar, Gyanendra [2 ]
机构
[1] Netaji Subhas Univ Technol, Dept Comp Sci & Engn, New Delhi 110078, India
[2] Manipal Univ Jaipur, Dept IoT & Intelligent Syst, Jaipur, Rajasthan, India
关键词
IoT; DAD; Stateless IPv6 addressing; Assigned address; Tentative address; DDOS ATTACKS; PROTOCOL;
D O I
10.1080/03772063.2024.2350931
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
In constrained IoT networks, Stateless Address Autoconfiguration (SLAAC) utilizes the Duplicate Address Detection (DAD) protocol to ensure the uniqueness of IPv6 addresses. However, the DAD employed in SLAAC is susceptible to various security vulnerabilities, including issues related to confidentiality, conflicting addresses, and spoofing attacks. Malicious nodes can exploit these weaknesses to perform Denial of Service (DoS) attacks by consistently claiming a tentative address, joining with conflicting address, or disclosing assigned address. Existing measures against DAD attacks have limitations, e.g. high computation, communication overhead, energy consumption, and major protocol modification. To address these challenges, this paper presents an innovative Optimized DAD (O-DAD) that is robust, scalable, and compliant with standard specifications. In O-DAD, the uniqueness of tentative IPv6 addresses is ensured in a way that neither new nor existing nodes have knowledge of each other's exact assigned addresses. O-DAD also hampers the ability of malicious nodes to spoof new/existing nodes. Experimental results demonstrate that the proposed solution effectively mitigates these attacks and exhibits superior performance in terms of Address Success Ratio (ASR), computational complexity, overhead, and energy consumption. When compared to Secure, Improved, and Standard DAD, the proposed scheme reduces overhead and energy by approximately 6%, 8%, and 15%, respectively.
引用
收藏
页码:7231 / 7256
页数:26
相关论文
共 58 条
  • [1] Abdulla Shubair A., 2017, International Journal of Security and Networks, V12, P83
  • [2] SEUI-64, bits an IPv6 addressing strategy to mitigate reconnaissance attacks
    Abdullah, Shubair A.
    [J]. ENGINEERING SCIENCE AND TECHNOLOGY-AN INTERNATIONAL JOURNAL-JESTECH, 2019, 22 (02): : 667 - 672
  • [3] IPv6 Cryptographically Generated Address: Analysis, Optimization and Protection
    Ahmed, Amjed Sid
    Hassan, Rosilah
    Qamar, Faizan
    Malik, Mazhar
    [J]. CMC-COMPUTERS MATERIALS & CONTINUA, 2021, 68 (01): : 247 - 265
  • [4] IPv6 Neighbor Discovery Protocol Specifications, Threats and Countermeasures: A Survey
    Ahmed, Amjed Sid Ahmed Mohamed Sid
    Hassan, Rosilah
    Othman, Nor Effendy
    [J]. IEEE ACCESS, 2017, 5 : 18187 - 18210
  • [5] Match-Prevention Technique Against Denial-of-Service Attack on Address Resolution and Duplicate Address Detection Processes in IPv6 Link-Local Network
    Al-Ani, Ahmed K.
    Anbar, Mohammed
    Al-Ani, Ayman
    Ibrahim, Dyala R.
    [J]. IEEE ACCESS, 2020, 8 : 27122 - 27138
  • [6] Proposed DAD-match Security Technique based on Hash Function to Secure Duplicate Address Detection in IPv6 Link-local Network
    Al-Ani, Ahmed K.
    Anbar, Mohammed
    Manickam, Selvakumar
    Al-Ani, Ayman
    Leau, Yu-Beng
    [J]. PROCEEDINGS OF THE 2017 INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY (ICIT 2017), 2017, : 175 - 179
  • [7] DAD-match; Security technique to prevent denial of service attack on duplicate address detection process in IPv6 link-local network
    Al-Ani, Ahmed K.
    Anbar, Mohammed
    Manickam, Selvakumar
    Al-Ani, Ayman
    [J]. PLOS ONE, 2019, 14 (04):
  • [8] NDPsec: Neighbor Discovery Protocol Security Mechanism
    Al-Ani, Ayman
    Al-Ani, Ahmed K.
    Laghari, Shams A.
    Manickam, Selvakumar
    Lai, Khin Wee
    Hasikin, Khairunnisa
    [J]. IEEE ACCESS, 2022, 10 : 83650 - 83663
  • [9] Al-Shareeda M.A., 2023, INFORMATICA, V29, P518, DOI [10.11591/ijeecs.v29.i1.pp518-526, DOI 10.31449/INF.V46I9.4441]
  • [10] Asati R., RFC, V7527