ON DHCP SECURITY

被引:0
|
作者
Dinu, Dumitru Daniel [1 ]
Togan, Mihai [1 ]
Bica, Ion [1 ]
机构
[1] Mil Tech Acad, Dept Comp Sci, Bucharest, Romania
关键词
DHCP; authentication module; authentication option; trust model; digital signature; replay detection; PKI; PGP;
D O I
暂无
中图分类号
O [数理科学和化学]; P [天文学、地球科学]; Q [生物科学]; N [自然科学总论];
学科分类号
07 ; 0710 ; 09 ;
摘要
Despite the security issues it has, DHCP is one of the most used protocols because it facilitates the automatic allocation of the configuration information in a network. While the number of mobile devices connected to Internet is increasing exponentially, the widespread adoption of IPv6 will take a lot of time. In this context, the need for good security mechanisms that prevents the known attacks against DHCP raises. In this paper we present an overview of the previous solutions to secure the protocol and, in the same time, we identify the reasons why each of these attempts failed. Based on the previous work missteps, we define a set of requirements for a practical and efficient authentication module for DHCP. Then we introduce a simple and flexible module that allows authentication of DHCP messages using two different trust models: PKI and PGP. We implemented and evaluated the proposed authentication module using different key types and sizes in the two trust models. The comprehensive results show that the proposed authentication module does not affect the protocol operation, but provides the so necessary security that DHCP lacks.
引用
收藏
页码:403 / 412
页数:10
相关论文
共 50 条
  • [1] Leveraging SDN to Improve the Security of DHCP
    Cox, Jacob H., Jr.
    Clark, Russell J.
    Owen, Henry L., III
    SDN-NFV SECURITY'16: PROCEEDINGS OF THE 2016 ACM INTERNATIONAL WORKSHOP ON SECURITY IN SOFTWARE DEFINED NETWORKS & NETWORK FUNCTION VIRTUALIZATION, 2016, : 35 - 38
  • [2] Application of Option 82 in DHCP Security Mechanism
    Cai Fei
    Liu Tieying
    ITESS: 2008 PROCEEDINGS OF INFORMATION TECHNOLOGY AND ENVIRONMENTAL SYSTEM SCIENCES, PT 1, 2008, : 648 - 653
  • [3] Study on Availability and Security of DHCP System In Campus Network
    Chen, Xiaozhong
    Mao, Zhijian
    PROCEEDINGS OF THE 2015 INTERNATIONAL CONFERENCE ON ELECTRONIC SCIENCE AND AUTOMATION CONTROL, 2015, 20 : 44 - 47
  • [4] Design and Implementation of Improved Security Protocols for DHCP Using Digital Certificates
    Duangphasuk, Surakarn
    Kungpisdan, Supakorn
    Hankla, Sumeena
    2011 17TH IEEE INTERNATIONAL CONFERENCE ON NETWORKS (ICON), 2011, : 287 - 292
  • [5] OTP_SAM: DHCP security authentication model based on OTP
    Zhang, Fuqiang
    Chen, Lin
    2016 IEEE 20th International Conference on Computer Supported Cooperative Work in Design (CSCWD), 2016, : 346 - 350
  • [6] Network security using E-DHCP over NAT/IPsec
    Demerjian, J
    Hajjeh, I
    Serhrouchni, A
    Badra, M
    IASTED International Conference on Web Technologies, Applications, and Services, 2005, : 53 - 58
  • [7] DHCP协议及DHCP RELAY
    梁金
    科技资讯, 2010, (12) : 29 - 29
  • [8] Security analysis of SDN controller-based DHCP services and attack mitigation with DHCPguard
    Tok, Mevlut Serkan
    Demirci, Mehmet
    COMPUTERS & SECURITY, 2021, 109
  • [9] 基于DHCP SNOOPING的DHCP网络部署
    孙雁杰
    刘良
    科技风, 2017, (06) : 93+114 - 93
  • [10] NDS and DHCP: configuring the DHCP service in NetWare 5
    NetWare Connection, 1999, 10 (04): : 18 - 26