Match-Prevention Technique Against Denial-of-Service Attack on Address Resolution and Duplicate Address Detection Processes in IPv6 Link-Local Network

被引:26
作者
Al-Ani, Ahmed K. [1 ]
Anbar, Mohammed [1 ]
Al-Ani, Ayman [1 ]
Ibrahim, Dyala R. [1 ]
机构
[1] Univ Sains Malaysia, Natl Adv IPv6 Ctr, Gelugor 11800, Malaysia
来源
IEEE ACCESS | 2020年 / 8卷
关键词
IPv6 link-local Network; neighbour discovery protocol; duplicate address detection; address resolution; DEFENSE-MECHANISMS;
D O I
10.1109/ACCESS.2020.2970787
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Address Resolution (AR) and Duplicate Address Detection (DAD) are considered the most important processes in Neighbour Discovery Protocol (NDP), which occurs frequently from each Internet Protocol version 6 (IPv6) host communicating with other neighbouring hosts. Two NDP messages are used during AR and DAD to communicate with one another in the same IPv6 link-local network, namely Neighbour Solicitation (NS) and Neighbour Advertisement (NA) messages. However, NDP messages have non-secure designs and lack verification mechanisms for authenticating whether incoming messages originate from a legitimate or illegitimate node. Therefore, any node in the same link can manipulate NS or NA messages and then launch a Denial-of-Service (DoS) attack. Techniques proposed to secure AR and DAD include Secure NDP (SeND) and Trust-NDP (Trust-ND); however, these techniques either entail high processing time and bandwidth consumption or are vulnerable to DoS attacks because of their designs. Therefore, to secure AR and DAD, this study aims to introduce a prevention technique called Match-Prevention, which secures target IP addresses and exchange messages (i.e. NS and NA). The processing time, bandwidth consumption and DoS prevention success rate of Match-Prevention in different scenarios are evaluated, and its performance is compared with those of existing techniques, including Standard-Process (i.e., Standard-AR and Standard-DAD), SeND and Trust-ND. Results show that Match-Prevention requires less processing time during AR and DAD processes and less bandwidth consumption compared with other existing techniques. In terms of DoS prevention success rate, the experiments show that Standard-Process and Trust-ND are unable to secure AR and DAD from DoS attacks, whilst SeND is vulnerable to flooding attacks. By contrast, Match-Prevention allows IPv6 nodes to verify the incoming message, discard the fake message before further processing and prevent a DoS attack during AR and DAD in an IPv6 link-local network.
引用
收藏
页码:27122 / 27138
页数:17
相关论文
共 36 条
  • [1] IPv6 Neighbor Discovery Protocol Specifications, Threats and Countermeasures: A Survey
    Ahmed, Amjed Sid Ahmed Mohamed Sid
    Hassan, Rosilah
    Othman, Nor Effendy
    [J]. IEEE ACCESS, 2017, 5 : 18187 - 18210
  • [2] Detection and Defense Mechanisms on Duplicate Address Detection Process in IPv6 Link-Local Network: A Survey on Limitations and Requirements
    Al-Ani, Ahmed K.
    Anbar, Mohammed
    Manickam, Selvakumar
    Wey, Chong Yung
    Leau, Yu-Beng
    Al-Ani, Ayman
    [J]. ARABIAN JOURNAL FOR SCIENCE AND ENGINEERING, 2019, 44 (04) : 3745 - 3763
  • [3] DAD-match; Security technique to prevent denial of service attack on duplicate address detection process in IPv6 link-local network
    Al-Ani, Ahmed K.
    Anbar, Mohammed
    Manickam, Selvakumar
    Al-Ani, Ayman
    [J]. PLOS ONE, 2019, 14 (04):
  • [4] Preventing Denial of Service Attacks on Address Resolution in IPv6 Link-local Network: AR-match Security Technique
    Al-Ani, Ahmed K.
    Anbar, Mohammed
    Manickam, Selvakumar
    Al-Ani, Ayman
    Leau, Yu-Beng
    [J]. COMPUTATIONAL SCIENCE AND TECHNOLOGY, 2019, 481 : 305 - 314
  • [5] Authentication and Privacy Approach for DHCPv6
    Al-Ani, Ayman
    Anbar, Mohammed
    Hasbullah, Iznan Husainy
    Abdullah, Rosni
    Al-Ani, Ahmed K.
    [J]. IEEE ACCESS, 2019, 7 : 73144 - 73156
  • [6] AlSa'deh A., 2012, P INT S FDN PRACT SE, P149
  • [7] AlSadeh A., 2013, THEORY PRACTICE CRYP, P178, DOI DOI 10.4018/978-1-4666-4030-6.CH008
  • [8] Review of Preventive Security Mechanisms for Neighbour Discovery Protocol
    Anbar, Mohammed
    Abdullah, Rosni
    Saad, Redhwan M. A.
    Hasbullah, Iznan H.
    [J]. ADVANCED SCIENCE LETTERS, 2017, 23 (11) : 11306 - 11310
  • [9] Open problems in hash function security
    Andreeva, Elena
    Mennink, Bart
    Preneel, Bart
    [J]. DESIGNS CODES AND CRYPTOGRAPHY, 2015, 77 (2-3) : 611 - 631
  • [10] [Anonymous], 2013, NETW SCI, DOI DOI 10.1007/S13119-013-0018-2