Enhance Neighbor Discovery Protocol Security by Using Secure Hash Algorithm

被引:3
作者
Usman, Muhammad [1 ]
Kamboh, Usman Rauf [1 ]
Taqdees, Muhammad Danish [1 ]
Waheed, Zain [1 ]
Shehzad, Mehboob Nazim [1 ]
Zafar, Hamza [1 ]
机构
[1] Univ Faisalabad, Dept Computat Sci, Faisalabad, Pakistan
来源
4TH INTERNATIONAL CONFERENCE ON INNOVATIVE COMPUTING (IC)2 | 2021年
关键词
Denial of Service; NDP; Neighbor Solicitation; SHA; Neighbor Advertisement; AR; DAD; SERVICE ATTACK; IPV6;
D O I
10.1109/ICIC53490.2021.9693085
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Neighbor Discovery Protocol (NDP) plays a vital role in IPv6. Neighbor Solicitation (NS) and Neighbor Advertisement (NA) are two important messages of NDP. Because these two messages are used in two major processes of NDP; Duplicate Address Detection (DAD) and Address Resolution (AR). DAD is used to assign a unique IPv6 address to a new device attached to the IPv6 link-local network. Whilst, AR works like ARP in IPv4, it is used to find the MAC Address of the device against an IPv6 Address. As the massage is multicast and there is no built-in security in NDP that's why it has vulnerabilities and due to lack of security any intruder can launch an attack; like the DoS (Denial of Service) attack which is most common. Many researches were conducted to resolve this issue, and techniques were proposed like SeND and Trust-ND. Some of these techniques can stop attacks but still have some vulnerabilities like high processing time and complexity etc. This research aims to introduce a technique that is more effective than already existing methods. This study proposed a security technique name as 64- bits Hash technique, to secure NS and NA messages of NDP by using SHA-512 for the encryption of target IPv6 and the use of only 64-bit of hashed value in NS and NA messages. The experimental results show that the purposed technique consumes less bandwidth and less processing time than other existing techniques to prevent DAD and AR from DoS attacks. The featured work is to implement the purposed technique on other processes of NDP and also to implement it on a large IPv6 network.
引用
收藏
页码:777 / 784
页数:8
相关论文
共 19 条
[1]   IPv6 Neighbor Discovery Protocol Specifications, Threats and Countermeasures: A Survey [J].
Ahmed, Amjed Sid Ahmed Mohamed Sid ;
Hassan, Rosilah ;
Othman, Nor Effendy .
IEEE ACCESS, 2017, 5 :18187-18210
[2]   Match-Prevention Technique Against Denial-of-Service Attack on Address Resolution and Duplicate Address Detection Processes in IPv6 Link-Local Network [J].
Al-Ani, Ahmed K. ;
Anbar, Mohammed ;
Al-Ani, Ayman ;
Ibrahim, Dyala R. .
IEEE ACCESS, 2020, 8 :27122-27138
[3]   Detection and Defense Mechanisms on Duplicate Address Detection Process in IPv6 Link-Local Network: A Survey on Limitations and Requirements [J].
Al-Ani, Ahmed K. ;
Anbar, Mohammed ;
Manickam, Selvakumar ;
Wey, Chong Yung ;
Leau, Yu-Beng ;
Al-Ani, Ayman .
ARABIAN JOURNAL FOR SCIENCE AND ENGINEERING, 2019, 44 (04) :3745-3763
[4]   Secure Neighbor Discovery: Review, Challenges, Perspectives, and Recommendations [J].
AlSa'deh, Ahmad ;
Meinel, Christoph .
IEEE SECURITY & PRIVACY, 2012, 10 (04) :26-34
[5]  
[Anonymous], 2007, P 2007 INT MULT COMP, DOI DOI 10.1109/ICCGI.2007.39
[6]  
[Anonymous], 2013, NETW SCI, DOI DOI 10.1007/S13119-013-0018-2
[7]  
[Anonymous], 2016, INT J SIMULATION SYS
[8]  
[Anonymous], 2013, 2013 ANN IEEE IND C
[9]  
[Anonymous], 2015, P 4 INT C INT APPL P
[10]  
Arkko J., 2005, SEcure Neighbor Discovery (SEND), RFC 3971