Cargando…
DAD-match; Security technique to prevent denial of service attack on duplicate address detection process in IPv6 link-local network
An efficiently unlimited address space is provided by Internet Protocol version 6 (IPv6). It aims to accommodate thousands of hundreds of unique devices on a similar link. This can be achieved through the Duplicate Address Detection (DAD) process. It is considered one of the core IPv6 network’s func...
Autores principales: | , , , |
---|---|
Formato: | Online Artículo Texto |
Lenguaje: | English |
Publicado: |
Public Library of Science
2019
|
Materias: | |
Acceso en línea: | https://www.ncbi.nlm.nih.gov/pmc/articles/PMC6445508/ https://www.ncbi.nlm.nih.gov/pubmed/30939154 http://dx.doi.org/10.1371/journal.pone.0214518 |
_version_ | 1783408210255806464 |
---|---|
author | Al-Ani, Ahmed K. Anbar, Mohammed Manickam, Selvakumar Al-Ani, Ayman |
author_facet | Al-Ani, Ahmed K. Anbar, Mohammed Manickam, Selvakumar Al-Ani, Ayman |
author_sort | Al-Ani, Ahmed K. |
collection | PubMed |
description | An efficiently unlimited address space is provided by Internet Protocol version 6 (IPv6). It aims to accommodate thousands of hundreds of unique devices on a similar link. This can be achieved through the Duplicate Address Detection (DAD) process. It is considered one of the core IPv6 network’s functions. It is implemented to make sure that IP addresses do not conflict with each other on the same link. However, IPv6 design’s functions are exposed to security threats like the DAD process, which is vulnerable to Denial of Service (DoS) attack. Such a threat prevents the host from configuring its IP address by responding to each Neighbor Solicitation (NS) through fake Neighbor Advertisement (NA). Various mechanisms have been proposed to secure the IPv6 DAD procedure. The proposed mechanisms, however, suffer from complexity, high processing time, and the consumption of more resources. The experiments-based findings revealed that all the existing mechanisms had failed to secure the IPv6 DAD process. Therefore, DAD-match security technique is proposed in this study to efficiently secure the DAD process consuming less processing time. DAD-match is built based on SHA-3 to hide the exchange tentative IP among hosts throughout the process of DAD in an IPv6 link-local network. The obtained experimental results demonstrated that the DAD-match security technique achieved less processing time compared with the existing mechanisms as it can resist a range of different threats like collision and brute-force attacks. The findings concluded that the DAD-match technique effectively prevents the DoS attack during the DAD process. The DAD-match technique is implemented on a small area IPv6 network; hence, the author future work is to implement and test the DAD-match technique on a large area IPv6 network. |
format | Online Article Text |
id | pubmed-6445508 |
institution | National Center for Biotechnology Information |
language | English |
publishDate | 2019 |
publisher | Public Library of Science |
record_format | MEDLINE/PubMed |
spelling | pubmed-64455082019-04-17 DAD-match; Security technique to prevent denial of service attack on duplicate address detection process in IPv6 link-local network Al-Ani, Ahmed K. Anbar, Mohammed Manickam, Selvakumar Al-Ani, Ayman PLoS One Research Article An efficiently unlimited address space is provided by Internet Protocol version 6 (IPv6). It aims to accommodate thousands of hundreds of unique devices on a similar link. This can be achieved through the Duplicate Address Detection (DAD) process. It is considered one of the core IPv6 network’s functions. It is implemented to make sure that IP addresses do not conflict with each other on the same link. However, IPv6 design’s functions are exposed to security threats like the DAD process, which is vulnerable to Denial of Service (DoS) attack. Such a threat prevents the host from configuring its IP address by responding to each Neighbor Solicitation (NS) through fake Neighbor Advertisement (NA). Various mechanisms have been proposed to secure the IPv6 DAD procedure. The proposed mechanisms, however, suffer from complexity, high processing time, and the consumption of more resources. The experiments-based findings revealed that all the existing mechanisms had failed to secure the IPv6 DAD process. Therefore, DAD-match security technique is proposed in this study to efficiently secure the DAD process consuming less processing time. DAD-match is built based on SHA-3 to hide the exchange tentative IP among hosts throughout the process of DAD in an IPv6 link-local network. The obtained experimental results demonstrated that the DAD-match security technique achieved less processing time compared with the existing mechanisms as it can resist a range of different threats like collision and brute-force attacks. The findings concluded that the DAD-match technique effectively prevents the DoS attack during the DAD process. The DAD-match technique is implemented on a small area IPv6 network; hence, the author future work is to implement and test the DAD-match technique on a large area IPv6 network. Public Library of Science 2019-04-02 /pmc/articles/PMC6445508/ /pubmed/30939154 http://dx.doi.org/10.1371/journal.pone.0214518 Text en © 2019 Al-Ani et al http://creativecommons.org/licenses/by/4.0/ This is an open access article distributed under the terms of the Creative Commons Attribution License (http://creativecommons.org/licenses/by/4.0/) , which permits unrestricted use, distribution, and reproduction in any medium, provided the original author and source are credited. |
spellingShingle | Research Article Al-Ani, Ahmed K. Anbar, Mohammed Manickam, Selvakumar Al-Ani, Ayman DAD-match; Security technique to prevent denial of service attack on duplicate address detection process in IPv6 link-local network |
title | DAD-match; Security technique to prevent denial of service attack on duplicate address detection process in IPv6 link-local network |
title_full | DAD-match; Security technique to prevent denial of service attack on duplicate address detection process in IPv6 link-local network |
title_fullStr | DAD-match; Security technique to prevent denial of service attack on duplicate address detection process in IPv6 link-local network |
title_full_unstemmed | DAD-match; Security technique to prevent denial of service attack on duplicate address detection process in IPv6 link-local network |
title_short | DAD-match; Security technique to prevent denial of service attack on duplicate address detection process in IPv6 link-local network |
title_sort | dad-match; security technique to prevent denial of service attack on duplicate address detection process in ipv6 link-local network |
topic | Research Article |
url | https://www.ncbi.nlm.nih.gov/pmc/articles/PMC6445508/ https://www.ncbi.nlm.nih.gov/pubmed/30939154 http://dx.doi.org/10.1371/journal.pone.0214518 |
work_keys_str_mv | AT alaniahmedk dadmatchsecuritytechniquetopreventdenialofserviceattackonduplicateaddressdetectionprocessinipv6linklocalnetwork AT anbarmohammed dadmatchsecuritytechniquetopreventdenialofserviceattackonduplicateaddressdetectionprocessinipv6linklocalnetwork AT manickamselvakumar dadmatchsecuritytechniquetopreventdenialofserviceattackonduplicateaddressdetectionprocessinipv6linklocalnetwork AT alaniayman dadmatchsecuritytechniquetopreventdenialofserviceattackonduplicateaddressdetectionprocessinipv6linklocalnetwork |