NDPsec: Neighbor Discovery Protocol Security Mechanism

被引:7
作者
Al-Ani, Ayman [1 ]
Al-Ani, Ahmed K. [2 ]
Laghari, Shams A. [3 ]
Manickam, Selvakumar [3 ]
Lai, Khin Wee [4 ]
Hasikin, Khairunnisa [4 ]
机构
[1] Univ Malaysia Sabah, Fac Comp & Informat, Kota Kinabalu 88400, Sabah, Malaysia
[2] Xiamen Univ Malaysia, Sch Comp & Data Sci, Sepang 43900, Selangor, Malaysia
[3] Univ Sains Malaysia USM, Natl Adv IPv6 Ctr NAv6, Gelugor 11800, Penang, Malaysia
[4] Univ Malaya, Fac Engn, Dept Biomed Engn, Kuala Lumpur 50603, Malaysia
关键词
Protocols; IP networks; Security; Internet; Local area networks; Routing protocols; Denial-of-service attack; Authentication; IPv6; NDP; denial of service; RA flooding; security; authentication; MITM; DEFENSE-MECHANISMS; ICMPV6-BASED DOS; DDOS ATTACKS; IPV6;
D O I
10.1109/ACCESS.2022.3196028
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Internet Protocol version 6 (IPv6) is envisioned as the cornerstone for future internet connectivity and information technology (IT) expansion. Due to its enormous address pool, extendable headers, high level of security, and mobility, IPv6 is positioned as the next-generation Internet Protocol. NDP is an integral component of IPv6 since it resolves addresses, locates routers, and finds duplicated addresses in a local-link network. Because NDP is based on the premise that all nodes in the network are trustworthy, it is subject to a variety of attacks, including Denial of Service (DoS) on Duplicate Address Detection (DAD) attacks (aka. DoS-on-DAD), Address Resolution-based attacks, Router Advertisement (RA) based attacks, and Redirect attacks. This paper proposes an NDP security (NDPsec) mechanism based on the Ed25519 digital signature to authenticate IPv6 hosts to prevent unauthorized devices from joining the network. The proposed NDPsec mechanism is evaluated and compared to Secure NDP (SeND), Match-Prevention, and Trust-ND mechanisms. The performance is measured in terms of processing time, traffic overhead, and resilience against network-based attacks. The results obtained from the experiments showed that NDPsec successfully prevented cyberattacks, with approximately 144% less processing time and over 50% less traffic overhead compared to SeND (the default security mechanism for NDP protocol). The proposed NDPsec mechanism has remarkable superiority in terms of resilience against attacks compared to Match-Prevention and Trust-ND mechanisms.
引用
收藏
页码:83650 / 83663
页数:14
相关论文
共 36 条
  • [1] Abusafat F., 2021, 2021 IEEE INT IOT EL, P1, DOI [10.1109/IEMTRONICS52119.2021, DOI 10.1109/IEMTRONICS52119.2021]
  • [2] Comparing the Usability of Cryptographic APIs
    Acar, Yasemin
    Backes, Michael
    Fahl, Sascha
    Garfinkel, Simson
    Kim, Doowon
    Mazurek, Michelle L.
    Stransky, Christian
    [J]. 2017 IEEE SYMPOSIUM ON SECURITY AND PRIVACY (SP), 2017, : 154 - 171
  • [3] IPv6 Neighbor Discovery Protocol Specifications, Threats and Countermeasures: A Survey
    Ahmed, Amjed Sid Ahmed Mohamed Sid
    Hassan, Rosilah
    Othman, Nor Effendy
    [J]. IEEE ACCESS, 2017, 5 : 18187 - 18210
  • [4] Match-Prevention Technique Against Denial-of-Service Attack on Address Resolution and Duplicate Address Detection Processes in IPv6 Link-Local Network
    Al-Ani, Ahmed K.
    Anbar, Mohammed
    Al-Ani, Ayman
    Ibrahim, Dyala R.
    [J]. IEEE ACCESS, 2020, 8 : 27122 - 27138
  • [5] Detection and Defense Mechanisms on Duplicate Address Detection Process in IPv6 Link-Local Network: A Survey on Limitations and Requirements
    Al-Ani, Ahmed K.
    Anbar, Mohammed
    Manickam, Selvakumar
    Wey, Chong Yung
    Leau, Yu-Beng
    Al-Ani, Ayman
    [J]. ARABIAN JOURNAL FOR SCIENCE AND ENGINEERING, 2019, 44 (04) : 3745 - 3763
  • [6] DAD-match; Security technique to prevent denial of service attack on duplicate address detection process in IPv6 link-local network
    Al-Ani, Ahmed K.
    Anbar, Mohammed
    Manickam, Selvakumar
    Al-Ani, Ayman
    [J]. PLOS ONE, 2019, 14 (04):
  • [7] Mechanism to prevent the abuse of IPv6 fragmentation in OpenFlow networks
    Al-Ani, Ayman
    Anbar, Mohammed
    Laghari, Shams A.
    Al-Ani, Ahmed K.
    [J]. PLOS ONE, 2020, 15 (05):
  • [8] DHCPv6Auth: a mechanism to improve DHCPv6 authentication and privacy
    Al-Ani, Ayman
    Anbar, Mohammed
    Al-Ani, Ahmed K.
    Hasbullah, Iznan Husainy
    [J]. SADHANA-ACADEMY PROCEEDINGS IN ENGINEERING SCIENCES, 2020, 45 (01):
  • [9] Authentication and Privacy Approach for DHCPv6
    Al-Ani, Ayman
    Anbar, Mohammed
    Hasbullah, Iznan Husainy
    Abdullah, Rosni
    Al-Ani, Ahmed K.
    [J]. IEEE ACCESS, 2019, 7 : 73144 - 73156
  • [10] AlS'adeh Ahmad, 2013, Foundations and Practice of Security. 5th International Symposium, FPS 2012. Revised Selected Papers, P149, DOI 10.1007/978-3-642-37119-6_10