Securing IPv6 Neighbor Discovery and SLAAC in Access Networks through SDN

被引:3
|
作者
Nelle, Daniel [1 ]
Seheffler, Thomas [2 ]
机构
[1] Univ Potsdam, Potsdam, Germany
[2] Hsch Tech & Wirtschaft Berlin, Berlin, Germany
关键词
D O I
10.1145/3340301.3341132
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
This paper proposes and evaluates a new approach, based on Software Defined Networking (SDN), to secure the IPv6 Neighbor Discovery Protocol (NDP) message exchange and make the Stateless Address Autoconfiguration safer. We created an SDN application on the Ryu SDN framework which functions as an intelligent NDP-Proxy. The SDN application inspects all NDP messages in the data path of the access switch. Once the application has accumulated data about the respective network segment, it performs sanity checking and filtering. We used several relevant attacks from the THC IPv6 toolkit to assert resiliency against attacks on the Neighbor Discovery Protocol. Load tests showed that the overhead for the NDP packet inspection is not neglectable, but once the relevant flow-rules have been installed, subsequent packets are forwarded on the fast-path of the switch and network performance is only minimally affected.
引用
收藏
页码:23 / 29
页数:7
相关论文
共 50 条
  • [31] Design and implementation of IPv6 neighbor discovery protocol supporting security function
    Kim, JM
    Park, IK
    Yu, JW
    Park, JH
    6TH INTERNATIONAL CONFERENCE ON ADVANCED COMMUNICATION TECHNOLOGY, VOLS 1 AND 2, PROCEEDINGS: BROADBAND CONVERGENCE NETWORK INFRASTRUCTURE, 2004, : 323 - 326
  • [32] IPv6 neighbor discovery protocol for common prefix allocation in IEEE 802.16
    Jeon, H
    Jee, J
    8th International Conference on Advanced Communication Technology, Vols 1-3: TOWARD THE ERA OF UBIQUITOUS NETWORKS AND SOCIETIES, 2006, : U1661 - U1663
  • [33] Providing Internet access to IPv6 mobile personal area networks through UMTS
    Alexiou, N
    Tsiouris, G
    Sykas, E
    PERSONAL WIRELESS COMMUNICATIONS, PROCEEDINGS, 2003, 2775 : 640 - 650
  • [34] Large Scale Topology Discovery for Public IPv6 Networks
    Liu, Zhenshan
    Luo, Junyong
    Wang, Qingxian
    ICN 2008: SEVENTH INTERNATIONAL CONFERENCE ON NETWORKING, PROCEEDINGS, 2008, : 639 - 644
  • [35] A new distributed topology discovery technology for IPv6 networks
    Liu, Zhenshan
    Wang, Qingxian
    Luo, Junyong
    PROCEEDINGS IEEE SOUTHEASTCON 2007, VOLS 1 AND 2, 2007, : 627 - 632
  • [36] Leveraging Proxy Mobile IPv6 with SDN
    Raza, Syed M.
    Kim, Dongsoo S.
    Shin, DongRyeol
    Choo, Hyunseung
    JOURNAL OF COMMUNICATIONS AND NETWORKS, 2016, 18 (03) : 460 - 475
  • [37] Securing Mobile IPv6 Route Optimization
    Wong, K. Daniel
    GLOBECOM 2006 - 2006 IEEE GLOBAL TELECOMMUNICATIONS CONFERENCE, 2006,
  • [38] Hierarchical access authentication method in mobile IPv6 networks
    Zhang, Hanwen
    Zhang, Yujun
    Tian, Ye
    Xiao, Wenshu
    Li, Zhongcheng
    Jisuanji Yanjiu yu Fazhan/Computer Research and Development, 2007, 44 (01): : 51 - 57
  • [39] An access control architecture for microcellular wireless IPv6 networks
    Schmid, S
    Finney, J
    Wu, M
    Friday, A
    Scott, AC
    Shepherd, WD
    LCN 2001: 26TH ANNUAL IEEE CONFERENCE ON LOCAL COMPUTER NETWORKS, PROCEEDINGS, 2001, : 454 - 463
  • [40] An IPv6 data plane for service aware access networks
    Stevens, T
    Vlaeminck, K
    Van De Meerssche, W
    De Turck, F
    Dhoedt, B
    Demeester, P
    ICOMP '05: PROCEEDINGS OF THE 2005 INTERNATIONAL CONFERENCE ON INTERNET COMPUTING, 2005, : 279 - 284