An SDN-Based Authentication Mechanism for Securing Neighbor Discovery Protocol in IPv6

被引:62
|
作者
Lu, Yiqin [1 ]
Wang, Meng [1 ]
Huang, Pengsen [1 ]
机构
[1] South China Univ Technol, Guangzhou, Guangdong, Peoples R China
关键词
D O I
10.1155/2017/5838657
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The Neighbor Discovery Protocol (NDP) is one of the main protocols in the Internet Protocol version 6 (IPv6) suite, and it provides many basic functions for the normal operation of IPv6 in a local area network (LAN), such as address autoconfiguration and address resolution. However, it has many vulnerabilities that can be used by malicious nodes to launch attacks, because the NDP messages are easily spoofed without protection. Surrounding this problem, many solutions have been proposed for securing NDP, but these solutions either proposed new protocols that need to be supported by all nodes or built mechanisms that require the cooperation of all nodes, which is inevitable in the traditional distributed networks. Nevertheless, Software-Defined Networking (SDN) provides a new perspective to think about protecting NDP. In this paper, we proposed an SDN-based authentication mechanism to verify the identity of NDP packets transmitted in a LAN. Using the centralized control and programmability of SDN, it can effectively prevent the spoofing attacks and other derived attacks based on spoofing. In addition, this mechanism needs no additional protocol supporting or configuration at hosts and routers and does not introduce any dedicated devices.
引用
收藏
页数:9
相关论文
共 50 条
  • [1] A SDN-Based Hierarchical Authentication Mechanism for IPv6 Address
    Liang, Xiao
    Chen, Heyao
    2019 IEEE INTERNATIONAL CONFERENCE ON INTELLIGENCE AND SECURITY INFORMATICS (ISI), 2019, : 225 - 225
  • [2] Securing IPv6 Neighbor Discovery and SLAAC in Access Networks through SDN
    Nelle, Daniel
    Seheffler, Thomas
    PROCEEDINGS OF THE 2019 APPLIED NETWORKING RESEARCH WORKSHOP, ANRW 2019, 2019, : 23 - 29
  • [3] Neighbor discovery protocol of IPv6
    Zhang, Yaobi
    Zhuang, Xiaotong
    Jisuanji Gongcheng/Computer Engineering, 2000, 26 (02): : 11 - 12
  • [4] Optimization of IPv6 Neighbor Discovery Protocol
    Machana, Jithender Reddy
    Narsimha, G.
    JOURNAL OF INTERCONNECTION NETWORKS, 2022, 22 (SUPP01)
  • [5] Security Analysis for IPv6 Neighbor Discovery Protocol
    Feng Xiaorong
    Lin Jun
    Jia Shizhun
    2013 2ND INTERNATIONAL SYMPOSIUM ON INSTRUMENTATION AND MEASUREMENT, SENSOR NETWORK AND AUTOMATION (IMSNA), 2013, : 303 - 307
  • [6] Research on IPv6 Neighbor Discovery Protocol (NDP) Security
    Zhang, Tao
    Wang, Zhilong
    2016 2ND IEEE INTERNATIONAL CONFERENCE ON COMPUTER AND COMMUNICATIONS (ICCC), 2016, : 2032 - 2035
  • [7] Comparing ARP of IPv4 with neighbor discovery protocol of IPv6
    Yin, C.
    Gong, H.
    Jiang, L.
    Changsha Dianli Xueyuan Xuebao/Journal of Changsha University of Electric Power, 2001, 16 (01): : 23 - 26
  • [8] IMPLEMENTATION OF TRUST NEIGHBOR DISCOVERY ON SECURING IPv6 LINK LOCAL COMMUNICATION
    Praptodiyon, Supriyanto
    Firmansyah, Teguh
    Hasbullah, Iznan H.
    Murugesan, Raja Kumar
    Osman, Azlan
    Wey, Chong Yung
    JOURNAL OF ENGINEERING SCIENCE AND TECHNOLOGY, 2018, 13 (09) : 2898 - 2915
  • [9] IPv6 Neighbor Discovery Protocol Specifications, Threats and Countermeasures: A Survey
    Ahmed, Amjed Sid Ahmed Mohamed Sid
    Hassan, Rosilah
    Othman, Nor Effendy
    IEEE ACCESS, 2017, 5 : 18187 - 18210
  • [10] Reliable Behavioral Dataset for IPv6 Neighbor Discovery Protocol Investigation
    Najjar, Firas
    Kadhum, Mohammad M.
    2015 5TH INTERNATIONAL CONFERENCE ON IT CONVERGENCE AND SECURITY (ICITCS), 2015,