Securing IPv6 Neighbor Discovery and SLAAC in Access Networks through SDN

被引:3
|
作者
Nelle, Daniel [1 ]
Seheffler, Thomas [2 ]
机构
[1] Univ Potsdam, Potsdam, Germany
[2] Hsch Tech & Wirtschaft Berlin, Berlin, Germany
关键词
D O I
10.1145/3340301.3341132
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
This paper proposes and evaluates a new approach, based on Software Defined Networking (SDN), to secure the IPv6 Neighbor Discovery Protocol (NDP) message exchange and make the Stateless Address Autoconfiguration safer. We created an SDN application on the Ryu SDN framework which functions as an intelligent NDP-Proxy. The SDN application inspects all NDP messages in the data path of the access switch. Once the application has accumulated data about the respective network segment, it performs sanity checking and filtering. We used several relevant attacks from the THC IPv6 toolkit to assert resiliency against attacks on the Neighbor Discovery Protocol. Load tests showed that the overhead for the NDP packet inspection is not neglectable, but once the relevant flow-rules have been installed, subsequent packets are forwarded on the fast-path of the switch and network performance is only minimally affected.
引用
收藏
页码:23 / 29
页数:7
相关论文
共 50 条
  • [41] Easy-SEND: A Didactic Implementation of the Secure Neighbor Discovery Protocol for IPv6
    Chiu, Say
    Gamess, Eric
    WCECS 2009: WORLD CONGRESS ON ENGINEERING AND COMPUTER SCIENCE, VOLS I AND II, 2009, : 260 - +
  • [42] A NEW TOPOLOGY DISCOVERY SOLUTION FOR IPv4 & IPv6 COEXISTING NETWORKS
    Chen, Guanlan
    Zhao, Qin
    Ma, Yan
    Ke, Hongli
    PROCEEDINGS OF THE 2010 INTERNATIONAL CONFERENCE ON ADVANCED INTELLIGENCE AND AWARENESS INTERNET, AIAI2010, 2010, : 208 - 212
  • [43] SDN-Ti: A General Solution Based on SDN to Attacker Traceback and Identification in IPv6 Networks
    Li, Chunlei
    Wu, Qian
    Li, Hewu
    Zhou, Jiang
    ICC 2019 - 2019 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2019,
  • [44] An evaluation of IPv6 multicast router in JGN IPv6 networks
    Mikamo, Y
    Hayashi, H
    Miyake, T
    Katsuno, S
    Kobayashi, K
    Esaki, H
    2004 INTERNATIONAL SYMPOSIUM ON APPLICATIONS AND THE INTERNET WORKSHOPS, PROCEEDINGS, 2004, : 146 - 152
  • [45] Deploying IPv6 Service Across Local IPv4 Access Networks
    Hamarsheh, Ala
    Goossens, Marnix
    Alasem, Rafe'
    RECENT RESEARCHES IN TELECOMMUNICATIONS, INFORMATICS, ELECTRONICS & SIGNAL PROCESSING, 2011, : 94 - +
  • [46] IPv4 and IPv6 Troubleshooting Enhancement through Reverse Path Discovery
    Valentini, F.
    Pratesi, M.
    Santucci, F.
    Ionta, T.
    2014 IEEE NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM (NOMS), 2014,
  • [47] Videoconference over IPv6 - IPv6 networks advanced developments
    Friacas, Carlos
    Baptista, Jose
    Domingues, Monica
    Ferreira, Paulo
    SIGMAP 2006: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON SIGNAL PROCESSING AND MULTIMEDIA APPLICATIONS, 2006, : 73 - +
  • [48] Securing 6LoWPAN Neighbor Discovery
    Park, Wang-Seok
    Park, Chang-Seop
    IEEE INTERNET OF THINGS JOURNAL, 2021, 8 (17) : 13677 - 13689
  • [49] IPv6 Operations and Deployment Scenarios over SDN
    Tseng, Chia-Wei
    Chen, Sheue-Ji
    Yang, Yao-Tsung
    Chou, Li-Der
    Shieh, Ce-Kuen
    Huang, Sheng-Wei
    2014 16TH ASIA-PACIFIC NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM (APNOMS), 2014,
  • [50] Signaling load of hierarchical mobile IPv6 protocol in IPv6 networks
    Kong, KS
    Roh, SJ
    Hwang, CS
    PERSONAL WIRELESS COMMUNICATIONS, PROCEEDINGS, 2004, 3260 : 440 - 450