An SDN-Based Authentication Mechanism for Securing Neighbor Discovery Protocol in IPv6

被引:62
|
作者
Lu, Yiqin [1 ]
Wang, Meng [1 ]
Huang, Pengsen [1 ]
机构
[1] South China Univ Technol, Guangzhou, Guangdong, Peoples R China
关键词
D O I
10.1155/2017/5838657
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The Neighbor Discovery Protocol (NDP) is one of the main protocols in the Internet Protocol version 6 (IPv6) suite, and it provides many basic functions for the normal operation of IPv6 in a local area network (LAN), such as address autoconfiguration and address resolution. However, it has many vulnerabilities that can be used by malicious nodes to launch attacks, because the NDP messages are easily spoofed without protection. Surrounding this problem, many solutions have been proposed for securing NDP, but these solutions either proposed new protocols that need to be supported by all nodes or built mechanisms that require the cooperation of all nodes, which is inevitable in the traditional distributed networks. Nevertheless, Software-Defined Networking (SDN) provides a new perspective to think about protecting NDP. In this paper, we proposed an SDN-based authentication mechanism to verify the identity of NDP packets transmitted in a LAN. Using the centralized control and programmability of SDN, it can effectively prevent the spoofing attacks and other derived attacks based on spoofing. In addition, this mechanism needs no additional protocol supporting or configuration at hosts and routers and does not introduce any dedicated devices.
引用
收藏
页数:9
相关论文
共 50 条
  • [21] A flexible IPv6 mobility management architecture for SDN-based 5G mobile networks
    Sajjad, Muhammad Mohtasim
    Jayalath, Dhammika
    Bernardos, Carlos J.
    TRANSACTIONS ON EMERGING TELECOMMUNICATIONS TECHNOLOGIES, 2022, 33 (03):
  • [22] Securing the Neighbour Discovery Protocol in IPv6 State-ful Address Auto-configuration
    Ahmed, Nadeem
    Sadiq, Adeel
    Farooq, Anum
    Akram, Rabia
    2017 16TH IEEE INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS / 11TH IEEE INTERNATIONAL CONFERENCE ON BIG DATA SCIENCE AND ENGINEERING / 14TH IEEE INTERNATIONAL CONFERENCE ON EMBEDDED SOFTWARE AND SYSTEMS, 2017, : 96 - 103
  • [23] Securing Video Streaming Over Internet Protocol Version 6(IPv6)
    Yong, Cheng Kian
    Abdullah, Azizol
    Abdullah, Mohd. Taufik
    INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2012, 12 (11): : 76 - 83
  • [24] Cross-domain authentication protocol based on certificate signcryption in Ipv6 Network
    Zhang, Longjun
    Xia, Ang
    International Journal of Advancements in Computing Technology, 2012, 4 (21) : 34 - 41
  • [25] Securing Vehicular IPv6 Communications
    Fernandez, Pedro J.
    Santa, Jose
    Bernal, Fernando
    Skarmeta, Antonio F.
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2016, 13 (01) : 46 - 58
  • [26] Proxy-Based IPv6 Neighbor Discovery Scheme for Wireless LAN Based Mesh Networks
    Lee, Jihoon
    Jeon, Seungwoo
    Kim, Jaehoon
    IEICE TRANSACTIONS ON COMMUNICATIONS, 2010, E93B (05) : 1151 - 1154
  • [27] ND plus plus - an extended IPv6 Neighbor Discovery protocol for enhanced stateless address autoconfiguration in MANETs
    Grajzer, Monika
    Zernicki, Tomasz
    Glabowski, Mariusz
    INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2014, 27 (10) : 2269 - 2288
  • [28] Securing SDN-Based IoT Group Communication
    Alzahrani, Bander
    Fotiou, Nikos
    FUTURE INTERNET, 2021, 13 (08):
  • [29] Improved Authentication of Binding Update Protocol in Mobile IPv6 Networks
    Dong Chun Lee
    Kuinam J. Kim
    Wireless Personal Communications, 2017, 94 : 351 - 367
  • [30] Improved Authentication of Binding Update Protocol in Mobile IPv6 Networks
    Lee, Dong Chun
    Kim, Kuinam J.
    WIRELESS PERSONAL COMMUNICATIONS, 2017, 94 (03) : 351 - 367