Securing IPv6 Neighbor Discovery and SLAAC in Access Networks through SDN

被引:3
|
作者
Nelle, Daniel [1 ]
Seheffler, Thomas [2 ]
机构
[1] Univ Potsdam, Potsdam, Germany
[2] Hsch Tech & Wirtschaft Berlin, Berlin, Germany
关键词
D O I
10.1145/3340301.3341132
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
This paper proposes and evaluates a new approach, based on Software Defined Networking (SDN), to secure the IPv6 Neighbor Discovery Protocol (NDP) message exchange and make the Stateless Address Autoconfiguration safer. We created an SDN application on the Ryu SDN framework which functions as an intelligent NDP-Proxy. The SDN application inspects all NDP messages in the data path of the access switch. Once the application has accumulated data about the respective network segment, it performs sanity checking and filtering. We used several relevant attacks from the THC IPv6 toolkit to assert resiliency against attacks on the Neighbor Discovery Protocol. Load tests showed that the overhead for the NDP packet inspection is not neglectable, but once the relevant flow-rules have been installed, subsequent packets are forwarded on the fast-path of the switch and network performance is only minimally affected.
引用
收藏
页码:23 / 29
页数:7
相关论文
共 50 条
  • [21] Reliable Behavioral Dataset for IPv6 Neighbor Discovery Protocol Investigation
    Najjar, Firas
    Kadhum, Mohammad M.
    2015 5TH INTERNATIONAL CONFERENCE ON IT CONVERGENCE AND SECURITY (ICITCS), 2015,
  • [22] Securing Vehicular IPv6 Communications
    Fernandez, Pedro J.
    Santa, Jose
    Bernal, Fernando
    Skarmeta, Antonio F.
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2016, 13 (01) : 46 - 58
  • [23] IPv6 Neighbor Discovery with Multi-hop Communication for IP-Based Vehicular Networks
    Xiang, Zhong
    Shen, Yiwen
    Jeong, Jaehoon
    2019 10TH INTERNATIONAL CONFERENCE ON INFORMATION AND COMMUNICATION TECHNOLOGY CONVERGENCE (ICTC): ICT CONVERGENCE LEADING THE AUTONOMOUS FUTURE, 2019, : 813 - 818
  • [24] Proxy-Based IPv6 Neighbor Discovery Scheme for Wireless LAN Based Mesh Networks
    Lee, Jihoon
    Jeon, Seungwoo
    Kim, Jaehoon
    IEICE TRANSACTIONS ON COMMUNICATIONS, 2010, E93B (05) : 1151 - 1154
  • [25] Research of Neighbor Discovery for IPv6 over Low-Power Wireless Personal Area Networks
    Luo, Bingqing
    Tang, Suning
    Sun, Zhixin
    PROCEEDINGS OF THE 11TH EAI INTERNATIONAL CONFERENCE ON HETEROGENEOUS NETWORKING FOR QUALITY, RELIABILITY, SECURITY AND ROBUSTNESS, 2015, : 233 - 238
  • [26] A DNS based new route optimization scheme with fast neighbor discovery in mobile IPv6 networks
    Park, Byungjoo
    Latchman, Haniph
    MANAGEMENT OF CONVERGENCE NETWORKS AND SERVICES, PROCEEDINGS, 2006, 4238 : 590 - 593
  • [27] A hierarchical topology discovery service for IPv6 networks
    Astic, I
    Festor, O
    NOMS 2002: IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM: MANAGEMENT SOLUTIONS FOR THE NEW COMMUNICATIONS WORLD, 2002, : 497 - 510
  • [28] Securing IPv6 Wireless Networks Against Malicious Router Advertisements
    Cavalcante, Jefferson
    Trajano, Alex F. R.
    Leite, Lucas
    Mariano, Miguel F.
    Celestino Junior, Joaquim
    Patel, Ahmed
    de Souza, Jose Neuman
    2019 IEEE 30TH ANNUAL INTERNATIONAL SYMPOSIUM ON PERSONAL, INDOOR AND MOBILE RADIO COMMUNICATIONS (PIMRC), 2019, : 489 - 494
  • [29] Impacts of mobility on wireless access to IPv6 networks
    Lazo, Christian R.
    Glockler, Roland
    SISTEMAS & TELEMATICA, 2006, 4 (08): : 101 - 112
  • [30] Monitoring emerging IPv6 wireless access networks
    Marques, P
    Castro, H
    Ricardo, M
    IEEE WIRELESS COMMUNICATIONS, 2005, 12 (01) : 47 - 53