An efficient CGA algorithm against DoS attack on Duplicate Address Detection process

Cui Zhang, Jinbo Xiong, Qiong Wu
{"title":"An efficient CGA algorithm against DoS attack on Duplicate Address Detection process","authors":"Cui Zhang, Jinbo Xiong, Qiong Wu","doi":"10.1109/WCNCW.2016.7552745","DOIUrl":null,"url":null,"abstract":"Neighbor Discovery Protocol (NDP) is significant in mobile network, which enables mobile node randomly access to foreign network by Stateless Link Address Autoconfiguration (SLAAC). However, the NDP initially offers no protection mechanism and is prone to address spoofing and Denial of Service (DoS). Secure Neighbor Discovery Protocol (SeNDP) is proposed to solve these NDP threats. Recently there are many solutions presented in SeNDP which relies on special IPv6 addresses named Cryptographically Generated Address (CGA). But there is little work to defend DoS attack on Duplicate Address Detection (DAD). In our paper, we focus on the problems of CGA and propose a novel time-based monitoring DoS attack. The conventional DoS defense mechanisms are realized by monitoring the packet rating and observing connection delay to analyze various DoS attack. Hence, we adopt a delay as an indication to distinct the DoS attack. We set a timer to control the address generation for monitoring abnormal attack to protect each address configuration. In addition, we adopt SHA-224 hash function instead of SHA-1 to improve the security of address generation. Considering the computation overhead, we decrease the hash matching factor from 16 bits to 8 bits. We develop our scheme using the Network Simulator (NS2) and the OpenSSL library. Finally, experiment results prove our scheme can provide more efficient IP generation. Compared with the CGA algorithm in SeNDP, our time consumption decreases to 10%. From the view of defense attack, our scheme can control DoS attack.","PeriodicalId":436094,"journal":{"name":"2016 IEEE Wireless Communications and Networking Conference Workshops (WCNCW)","volume":"31 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"1900-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2016 IEEE Wireless Communications and Networking Conference Workshops (WCNCW)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/WCNCW.2016.7552745","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2

Abstract

Neighbor Discovery Protocol (NDP) is significant in mobile network, which enables mobile node randomly access to foreign network by Stateless Link Address Autoconfiguration (SLAAC). However, the NDP initially offers no protection mechanism and is prone to address spoofing and Denial of Service (DoS). Secure Neighbor Discovery Protocol (SeNDP) is proposed to solve these NDP threats. Recently there are many solutions presented in SeNDP which relies on special IPv6 addresses named Cryptographically Generated Address (CGA). But there is little work to defend DoS attack on Duplicate Address Detection (DAD). In our paper, we focus on the problems of CGA and propose a novel time-based monitoring DoS attack. The conventional DoS defense mechanisms are realized by monitoring the packet rating and observing connection delay to analyze various DoS attack. Hence, we adopt a delay as an indication to distinct the DoS attack. We set a timer to control the address generation for monitoring abnormal attack to protect each address configuration. In addition, we adopt SHA-224 hash function instead of SHA-1 to improve the security of address generation. Considering the computation overhead, we decrease the hash matching factor from 16 bits to 8 bits. We develop our scheme using the Network Simulator (NS2) and the OpenSSL library. Finally, experiment results prove our scheme can provide more efficient IP generation. Compared with the CGA algorithm in SeNDP, our time consumption decreases to 10%. From the view of defense attack, our scheme can control DoS attack.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
重复地址检测过程中抗DoS攻击的有效CGA算法
邻居发现协议(NDP)在移动网络中具有重要意义,它通过无状态链路地址自动配置(SLAAC)实现移动节点随机访问外部网络。但是,NDP在初始阶段没有提供任何保护机制,容易受到欺骗和拒绝服务(DoS)攻击。为了解决这些威胁,提出了安全邻居发现协议(SeNDP)。最近在SeNDP中提出了许多基于特殊IPv6地址的解决方案,这些地址被称为加密生成地址(cryptographic Generated Address, CGA)。但是对于重复地址检测(DAD)的DoS攻击的防御工作却很少。本文针对CGA存在的问题,提出了一种基于时间的监控DoS攻击方法。传统的DoS防御机制是通过监测数据包评级和观察连接延迟来分析各种DoS攻击。因此,我们采用延迟作为区分DoS攻击的指示。通过设置定时器控制地址生成,监控异常攻击,保护每个地址配置。此外,我们采用SHA-224哈希函数代替SHA-1来提高地址生成的安全性。考虑到计算开销,我们将哈希匹配因子从16位减少到8位。我们使用网络模拟器(NS2)和OpenSSL库来开发我们的方案。实验结果表明,该方案能够提供更高效的IP生成。与SeNDP中的CGA算法相比,我们的时间消耗降低到10%。从防御攻击的角度来看,我们的方案可以控制DoS攻击。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Towards 5G-enabled Tactile Internet: Radio resource allocation for haptic communications A two dimensional beam scanning array antenna for 5G wireless communications Software Defined Networking for cognitive Radio over Fiber systems On the performance of downlink optical communication via relaying in the presence of pointing errors Channel measurements in an open-pit mine using USRPs: 5G - expect the unexpected
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1