Cargando…

DAD-match; Security technique to prevent denial of service attack on duplicate address detection process in IPv6 link-local network

An efficiently unlimited address space is provided by Internet Protocol version 6 (IPv6). It aims to accommodate thousands of hundreds of unique devices on a similar link. This can be achieved through the Duplicate Address Detection (DAD) process. It is considered one of the core IPv6 network’s func...

Descripción completa

Detalles Bibliográficos
Autores principales: Al-Ani, Ahmed K., Anbar, Mohammed, Manickam, Selvakumar, Al-Ani, Ayman
Formato: Online Artículo Texto
Lenguaje:English
Publicado: Public Library of Science 2019
Materias:
Acceso en línea:https://www.ncbi.nlm.nih.gov/pmc/articles/PMC6445508/
https://www.ncbi.nlm.nih.gov/pubmed/30939154
http://dx.doi.org/10.1371/journal.pone.0214518
_version_ 1783408210255806464
author Al-Ani, Ahmed K.
Anbar, Mohammed
Manickam, Selvakumar
Al-Ani, Ayman
author_facet Al-Ani, Ahmed K.
Anbar, Mohammed
Manickam, Selvakumar
Al-Ani, Ayman
author_sort Al-Ani, Ahmed K.
collection PubMed
description An efficiently unlimited address space is provided by Internet Protocol version 6 (IPv6). It aims to accommodate thousands of hundreds of unique devices on a similar link. This can be achieved through the Duplicate Address Detection (DAD) process. It is considered one of the core IPv6 network’s functions. It is implemented to make sure that IP addresses do not conflict with each other on the same link. However, IPv6 design’s functions are exposed to security threats like the DAD process, which is vulnerable to Denial of Service (DoS) attack. Such a threat prevents the host from configuring its IP address by responding to each Neighbor Solicitation (NS) through fake Neighbor Advertisement (NA). Various mechanisms have been proposed to secure the IPv6 DAD procedure. The proposed mechanisms, however, suffer from complexity, high processing time, and the consumption of more resources. The experiments-based findings revealed that all the existing mechanisms had failed to secure the IPv6 DAD process. Therefore, DAD-match security technique is proposed in this study to efficiently secure the DAD process consuming less processing time. DAD-match is built based on SHA-3 to hide the exchange tentative IP among hosts throughout the process of DAD in an IPv6 link-local network. The obtained experimental results demonstrated that the DAD-match security technique achieved less processing time compared with the existing mechanisms as it can resist a range of different threats like collision and brute-force attacks. The findings concluded that the DAD-match technique effectively prevents the DoS attack during the DAD process. The DAD-match technique is implemented on a small area IPv6 network; hence, the author future work is to implement and test the DAD-match technique on a large area IPv6 network.
format Online
Article
Text
id pubmed-6445508
institution National Center for Biotechnology Information
language English
publishDate 2019
publisher Public Library of Science
record_format MEDLINE/PubMed
spelling pubmed-64455082019-04-17 DAD-match; Security technique to prevent denial of service attack on duplicate address detection process in IPv6 link-local network Al-Ani, Ahmed K. Anbar, Mohammed Manickam, Selvakumar Al-Ani, Ayman PLoS One Research Article An efficiently unlimited address space is provided by Internet Protocol version 6 (IPv6). It aims to accommodate thousands of hundreds of unique devices on a similar link. This can be achieved through the Duplicate Address Detection (DAD) process. It is considered one of the core IPv6 network’s functions. It is implemented to make sure that IP addresses do not conflict with each other on the same link. However, IPv6 design’s functions are exposed to security threats like the DAD process, which is vulnerable to Denial of Service (DoS) attack. Such a threat prevents the host from configuring its IP address by responding to each Neighbor Solicitation (NS) through fake Neighbor Advertisement (NA). Various mechanisms have been proposed to secure the IPv6 DAD procedure. The proposed mechanisms, however, suffer from complexity, high processing time, and the consumption of more resources. The experiments-based findings revealed that all the existing mechanisms had failed to secure the IPv6 DAD process. Therefore, DAD-match security technique is proposed in this study to efficiently secure the DAD process consuming less processing time. DAD-match is built based on SHA-3 to hide the exchange tentative IP among hosts throughout the process of DAD in an IPv6 link-local network. The obtained experimental results demonstrated that the DAD-match security technique achieved less processing time compared with the existing mechanisms as it can resist a range of different threats like collision and brute-force attacks. The findings concluded that the DAD-match technique effectively prevents the DoS attack during the DAD process. The DAD-match technique is implemented on a small area IPv6 network; hence, the author future work is to implement and test the DAD-match technique on a large area IPv6 network. Public Library of Science 2019-04-02 /pmc/articles/PMC6445508/ /pubmed/30939154 http://dx.doi.org/10.1371/journal.pone.0214518 Text en © 2019 Al-Ani et al http://creativecommons.org/licenses/by/4.0/ This is an open access article distributed under the terms of the Creative Commons Attribution License (http://creativecommons.org/licenses/by/4.0/) , which permits unrestricted use, distribution, and reproduction in any medium, provided the original author and source are credited.
spellingShingle Research Article
Al-Ani, Ahmed K.
Anbar, Mohammed
Manickam, Selvakumar
Al-Ani, Ayman
DAD-match; Security technique to prevent denial of service attack on duplicate address detection process in IPv6 link-local network
title DAD-match; Security technique to prevent denial of service attack on duplicate address detection process in IPv6 link-local network
title_full DAD-match; Security technique to prevent denial of service attack on duplicate address detection process in IPv6 link-local network
title_fullStr DAD-match; Security technique to prevent denial of service attack on duplicate address detection process in IPv6 link-local network
title_full_unstemmed DAD-match; Security technique to prevent denial of service attack on duplicate address detection process in IPv6 link-local network
title_short DAD-match; Security technique to prevent denial of service attack on duplicate address detection process in IPv6 link-local network
title_sort dad-match; security technique to prevent denial of service attack on duplicate address detection process in ipv6 link-local network
topic Research Article
url https://www.ncbi.nlm.nih.gov/pmc/articles/PMC6445508/
https://www.ncbi.nlm.nih.gov/pubmed/30939154
http://dx.doi.org/10.1371/journal.pone.0214518
work_keys_str_mv AT alaniahmedk dadmatchsecuritytechniquetopreventdenialofserviceattackonduplicateaddressdetectionprocessinipv6linklocalnetwork
AT anbarmohammed dadmatchsecuritytechniquetopreventdenialofserviceattackonduplicateaddressdetectionprocessinipv6linklocalnetwork
AT manickamselvakumar dadmatchsecuritytechniquetopreventdenialofserviceattackonduplicateaddressdetectionprocessinipv6linklocalnetwork
AT alaniayman dadmatchsecuritytechniquetopreventdenialofserviceattackonduplicateaddressdetectionprocessinipv6linklocalnetwork