Securing IPv6 Neighbor Discovery and SLAAC in Access Networks through SDN

被引:3
|
作者
Nelle, Daniel [1 ]
Seheffler, Thomas [2 ]
机构
[1] Univ Potsdam, Potsdam, Germany
[2] Hsch Tech & Wirtschaft Berlin, Berlin, Germany
关键词
D O I
10.1145/3340301.3341132
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
This paper proposes and evaluates a new approach, based on Software Defined Networking (SDN), to secure the IPv6 Neighbor Discovery Protocol (NDP) message exchange and make the Stateless Address Autoconfiguration safer. We created an SDN application on the Ryu SDN framework which functions as an intelligent NDP-Proxy. The SDN application inspects all NDP messages in the data path of the access switch. Once the application has accumulated data about the respective network segment, it performs sanity checking and filtering. We used several relevant attacks from the THC IPv6 toolkit to assert resiliency against attacks on the Neighbor Discovery Protocol. Load tests showed that the overhead for the NDP packet inspection is not neglectable, but once the relevant flow-rules have been installed, subsequent packets are forwarded on the fast-path of the switch and network performance is only minimally affected.
引用
收藏
页码:23 / 29
页数:7
相关论文
共 50 条
  • [1] An SDN-Based Authentication Mechanism for Securing Neighbor Discovery Protocol in IPv6
    Lu, Yiqin
    Wang, Meng
    Huang, Pengsen
    SECURITY AND COMMUNICATION NETWORKS, 2017,
  • [2] IPv6 Neighbor Discovery for Prefix and Service Discovery in Vehicular Networks
    Jeong, Junsik
    Shen, Yiwen
    Jo, Younghwa
    Jeong, Jaehoon
    2016 INTERNATIONAL CONFERENCE ON INFORMATION AND COMMUNICATION TECHNOLOGY CONVERGENCE (ICTC 2016): TOWARDS SMARTER HYPER-CONNECTED WORLD, 2016, : 231 - 236
  • [3] IMPLEMENTATION OF TRUST NEIGHBOR DISCOVERY ON SECURING IPv6 LINK LOCAL COMMUNICATION
    Praptodiyon, Supriyanto
    Firmansyah, Teguh
    Hasbullah, Iznan H.
    Murugesan, Raja Kumar
    Osman, Azlan
    Wey, Chong Yung
    JOURNAL OF ENGINEERING SCIENCE AND TECHNOLOGY, 2018, 13 (09) : 2898 - 2915
  • [4] Neighbor discovery protocol of IPv6
    Zhang, Yaobi
    Zhuang, Xiaotong
    Jisuanji Gongcheng/Computer Engineering, 2000, 26 (02): : 11 - 12
  • [5] Neighbor Discovery for IPv6 over BLE Mesh Networks
    Luo, Bingqing
    Sun, Zhixin
    Pang, Yu
    Ahmad, Awais
    Lin, Jinzhao
    Wu, Jun
    Zhang, Hui
    APPLIED SCIENCES-BASEL, 2020, 10 (05):
  • [6] Securing IPv6 Neighbor Discovery Address Resolution with Voucher-Based Addressing
    Puhl, Zachary T.
    Guo, Jinhua
    NETWORK, 2024, 4 (03): : 338 - 366
  • [7] Neighbor discovery and stateless autoconfiguration in IPv6
    Narten, T
    IEEE INTERNET COMPUTING, 1999, 3 (04) : 54 - +
  • [8] Improving Security for IPv6 Neighbor Discovery
    Ahmed, Amjed Sid
    Hassan, Rosilah
    Othman, Nor Effendy
    5TH INTERNATIONAL CONFERENCE ON ELECTRICAL ENGINEERING AND INFORMATICS 2015, 2015, : 271 - 274
  • [9] Optimization of IPv6 Neighbor Discovery Protocol
    Machana, Jithender Reddy
    Narsimha, G.
    JOURNAL OF INTERCONNECTION NETWORKS, 2022, 22 (SUPP01)
  • [10] Efficient IPv6 Neighbor Discovery Scheme for Wireless LAN Mesh networks
    Lee, Jihoon
    2009 IEEE INTERNATIONAL CONFERENCE ON CONSUMER ELECTRONICS, 2009, : 291 - 292