Overview of IPv6 Based DDoS and DoS Attacks Detection Mechanisms

被引:7
|
作者
Bahashwan, Abdullah Ahmed [1 ]
Anbar, Mohammed [1 ]
Hanshi, Sabri M. [2 ]
机构
[1] Univ Sains Malaysia USM, Natl Adv IPv6 Ctr NAv6, Gelugor 11800, Penang, Malaysia
[2] Seiyun Community Coll, Hadhramaut, Yemen
来源
关键词
IPv6; ICMPv6; NDP; ICMPv6 based DDoS & DoS utilization; IDS; FRAMEWORK; SYSTEM;
D O I
10.1007/978-981-15-2693-0_11
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In recent years, the number of Internet users and devices are rapidly increased. For this reason, the Internet Assigned Number Authority (IANA) launched a new protocol called Internet Protocol version six (IPv6) next generation. The IPv6 provides new features that fit the internet revolution. IPv6 is equipped with new protocols such as Neighbor Discovery Protocol (NDP) and Internet Control Messages protocol version six (ICMPv6). In fact, ICMPv6 is considered as the backbone of the IPv6 protocol since it is responsible for many key functions like the NDP process. In addition, the NDP protocol is a stateless protocol that gives the lack of authentication to NDP messages, which is vulnerable to many types of attacks such as Distributed Denial of Services (DDoS) and Denial of Services (DoS) flooding attacks. In this type of attacks, the attacker sends an enormous volume of abnormal traffic to increase network congestion and break down the network. Under those circumstances, the first line of defense in a network has been supplemented by additional devices and tools that supervise the network activities and monitor the network traffic behaviors as well as to stop unauthorized intrusions. Overall, the aim of this review paper is to give pure thoughts about the IPv6 features and the most important related protocols like ICMPv6 protocol and NDP protocol. Also, this article discusses DDoS and DoS attack based on ICMPv6 protocol. Likewise, this article gives a comprehensive review of the IPv6 Intrusion Detection Systems based on DDoS & DoS attacks with their features and security limitations.
引用
收藏
页码:153 / 167
页数:15
相关论文
共 50 条
  • [1] On the Potential of IPv6 Open Resolvers for DDoS Attacks
    Hendriks, Luuk
    Schmidt, Ricardo de Oliveira
    van Rijswijk-Deij, Roland
    Pras, Aiko
    [J]. PASSIVE AND ACTIVE MEASUREMENT (PAM 2017), 2017, 10176 : 17 - 29
  • [2] IPv6的DoS/DDoS攻击及防御
    胡江涛
    [J]. 电脑编程技巧与维护, 2009, (20) : 111 - 112
  • [3] ICMPv6-Based DoS and DDoS Attacks and Defense Mechanisms: Review
    Elejla, Omar E.
    Anbar, Mohammed
    Belaton, Bahari
    [J]. IETE TECHNICAL REVIEW, 2017, 34 (04) : 390 - 407
  • [4] Detecting DoS/DDoS Attack under IPv4/IPv6 Translation Covert Channel
    Wang, Reen-cheng
    Chen, Bo-xian
    Huang, Bo-jyun
    Xie, Shi-yi
    Cho, Yu-tine
    [J]. 2016 2ND INTERNATIONAL CONFERENCE ON HUMANITY AND SOCIAL SCIENCE (ICHSS 2016), 2016, : 230 - 235
  • [5] Multi-addresses amplification DoS Attacks by native IPv6 and IPv6Tunnels
    Cui, Yu
    Zhang, Hongli
    Tian, Zhihong
    Fang, Binxing
    [J]. Jisuanji Yanjiu yu Fazhan/Computer Research and Development, 2014, 51 (07): : 1594 - 1603
  • [6] Novel Mechanism to Prevent Denial of Service (DoS) Attacks in IPv6 Duplicate Address Detection Process
    Ul Rehman, Shafiq
    Manickam, Selvakumar
    [J]. INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2016, 10 (04): : 143 - 153
  • [7] IPv6 DoS Attacks Detection Using Machine Learning Enhanced IDS in SDN/NFV Environment
    Tseng, Chia-Wei
    Wu, Li-Fan
    Hsu, Shih-Chun
    Yu, Sheng-Wang
    [J]. APNOMS 2020: 2020 21ST ASIA-PACIFIC NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM (APNOMS), 2020, : 263 - 266
  • [8] P4-NSAF: defending IPv6 networks against ICMPv6 DoS and DDoS attacks with P4
    Li, Yubing
    Yang, Wei
    Zhou, Zhou
    Liu, Qingyun
    Li, Zhao
    Li, Shu
    [J]. IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC 2022), 2022, : 5005 - 5010
  • [9] AN IMPROVED SEND PROTOCOL AGAINST DOS ATTACKS IN MOBILE IPV6 ENVIRONMENT
    Huang, Meigen
    Liu, Jianrong
    Zhou, Yunjie
    [J]. 2009 IEEE INTERNATIONAL CONFERENCE ON NETWORK INFRASTRUCTURE AND DIGITAL CONTENT, PROCEEDINGS, 2009, : 232 - +
  • [10] Dynamic IPv6 Activation based Defense for IPv6 Router Advertisement Flooding (DoS) Attack
    Goel, Jai Narayan
    Mehtre, B. M.
    [J]. 2014 IEEE INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE AND COMPUTING RESEARCH (IEEE ICCIC), 2014, : 628 - 632