【24h】

Security and privacy produced by DHCP unique identifiers

机译:DHCP唯一标识符产生的安全性和隐私性

获取原文

摘要

As protection against the current privacy weaknesses of StateLess Address AutoConfiguration (SLAAC) in the Internet Protocol version 6 (IPv6), network administrators may choose to deploy the new Dynamic Host Configuration Protocol for IPv6 (DHCPv6). Similar to the Dynamic Host Configuration Protocol (DHCP) for the Internet Protocol version 4 (IPv4), DHCPv6 uses a client-server model to manage addresses in networks, providing stateful address assignment. While DHCPv6 can be configured to assign randomly distributed addresses to clients, the DHCP Unique Identifier (DUID) was designed to identify uniquely identify clients to servers and remains static to clients as they move between different subnets and networks. Since the DUID is globally unique and exposed in the clear, attackers can geotemporally track clients by sniffing DHCPv6 messages on the local network or by using unauthenticated protocol-valid queries that request systems' DUIDs or leased addresses. DUIDs can also be formed with system-specific information, further compromising the privacy and security of the host. To combat the threat of the static DUID, a dynamic DUID was implemented and analyzed for its effect on privacy and security as well as its computational overhead. The privacy implications of DHCPv6 must be addressed before large-scale IPv6 deployment.
机译:为了防止Internet协议版本6(IPv6)中的StateLess地址自动配置(SLAAC)当前的隐私弱点,网络管理员可以选择部署新的IPv6动态主机配置协议(DHCPv6)。与Internet协议版本4(IPv4)的动态主机配置协议(DHCP)相似,DHCPv6使用客户端-服务器模型来管理网络中的地址,从而提供有状态的地址分配。虽然可以将DHCPv6配置为向客户端分配随机分配的地址,但DHCP唯一标识符(DUID)旨在识别服务器的唯一客户端,并在客户端在不同子网和网络之间移动时对客户端保持静态。由于DUID在全球范围内是唯一的并且是公开的,因此攻击者可以通过嗅探本地网络上的DHCPv6消息或使用请求系统DUID或租用地址的未经身份验证的协议有效查询来在地理上跟踪客户端。 DUID也可以由系统特定的信息组成,从而进一步损害了主机的隐私和安全性。为了对抗静态DUID的威胁,实施并分析了动态DUID对隐私和安全性的影响以及其计算开销。在大规模部署IPv6之前,必须解决DHCPv6的隐私问题。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号