首页> 美国卫生研究院文献>PLoS Clinical Trials >DAD-match; Security technique to prevent denial of service attack on duplicate address detection process in IPv6 link-local network
【2h】

DAD-match; Security technique to prevent denial of service attack on duplicate address detection process in IPv6 link-local network

机译:DAD匹配;在IPv6链路本地网络中防止对重复地址检测过程进行拒绝服务攻击的安全技术

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

An efficiently unlimited address space is provided by Internet Protocol version 6 (IPv6). It aims to accommodate thousands of hundreds of unique devices on a similar link. This can be achieved through the Duplicate Address Detection (DAD) process. It is considered one of the core IPv6 network’s functions. It is implemented to make sure that IP addresses do not conflict with each other on the same link. However, IPv6 design’s functions are exposed to security threats like the DAD process, which is vulnerable to Denial of Service (DoS) attack. Such a threat prevents the host from configuring its IP address by responding to each Neighbor Solicitation (NS) through fake Neighbor Advertisement (NA). Various mechanisms have been proposed to secure the IPv6 DAD procedure. The proposed mechanisms, however, suffer from complexity, high processing time, and the consumption of more resources. The experiments-based findings revealed that all the existing mechanisms had failed to secure the IPv6 DAD process. Therefore, DAD-match security technique is proposed in this study to efficiently secure the DAD process consuming less processing time. DAD-match is built based on SHA-3 to hide the exchange tentative IP among hosts throughout the process of DAD in an IPv6 link-local network. The obtained experimental results demonstrated that the DAD-match security technique achieved less processing time compared with the existing mechanisms as it can resist a range of different threats like collision and brute-force attacks. The findings concluded that the DAD-match technique effectively prevents the DoS attack during the DAD process. The DAD-match technique is implemented on a small area IPv6 network; hence, the author future work is to implement and test the DAD-match technique on a large area IPv6 network.
机译:Internet协议版本6(IPv6)提供了有效的无限地址空间。它旨在在类似的链接上容纳成千上万的独特设备。这可以通过重复地址检测(DAD)过程来实现。它被视为IPv6核心网络功能之一。它的实现是为了确保IP地址在同一链路上不会相互冲突。但是,IPv6设计的功能面临DAD流程等安全威胁,容易受到拒绝服务(DoS)攻击。这种威胁使主机无法通过伪造的邻居广告(NA)响应每个邻居请求(NS)来配置其IP地址。已经提出了各种机制来保护IPv6 DAD过程。然而,所提出的机制遭受复杂性,高处理时间以及消耗更多资源的困扰。基于实验的发现表明,所有现有机制都无法确保IPv6 DAD流程的安全。因此,在这项研究中提出了DAD匹配安全技术,以有效保护耗时更少的DAD流程。 DAD-match基于SHA-3构建,以在IPv6链路本地网络中的DAD整个过程中隐藏主机之间的交换暂定IP。获得的实验结果表明,与现有机制相比,DAD-match安全技术可减少处理时间,因为它可以抵抗各种不同的威胁,例如碰撞和蛮力攻击。研究结果得出结论,DAD匹配技术可以有效地防止DAD过程中的DoS攻击。 DAD匹配技术是在小区域IPv6网络上实现的;因此,作者未来的工作是在大范围的IPv6网络上实施和测试DAD匹配技术。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号