...
首页> 外文期刊>American journal of applied sciences >ENHANCING SECURITY FOR IPV6 NEIGHBOR DISCOVERY PROTOCOL USING CRYPTOGRAPHY
【24h】

ENHANCING SECURITY FOR IPV6 NEIGHBOR DISCOVERY PROTOCOL USING CRYPTOGRAPHY

机译:使用密码术增强IPV6近邻发现协议的安全性

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

Internet Protocol version 4 (IPv4) would gradually be replaced by Internet Protocol version 6 (IPv6) as the next generation of Internet protocol. The Neighbor Discovery Protocol (NDP), one of the main protocols in the IPv6 suite, comprises Neighbor Discovery for IPv6. NDP is used by both hosts and routers. Its functions include Neighbor Discovery (ND), Router Discovery (RD), Address Auto configuration, Address Resolution, Neighbor Unreachability Detection (NUD), Duplicate Address Detection (DAD) and Redirection. If not secured, NDP is vulnerable to various attacks: Neighbor Solicitation (NS) spoofing and Neighbor Advertisement (NS) spoofing, redirection, stealing addresses, denial of service are examples of these attacks. Since its early stages of designing and development NDP assumes connections between nodes will be safe but deployment stage prove this assumption is incorrect and highlight the security holes. This fact leads Internet Engineer Task Force (IETF) to request solutions in order to overcoming these drawbacks. SEcure Neighbor Discovery or SEND is then proposed, SEND solve a part of the threats associated with NDP and request for more researches to find a better solution that manage to forbid all these threats and ignore its limitations. This study presents a new mechanism to avoid security threats for IPv6 NDP based on digital signature procedures. The proposed solution is manage to eliminate the threats because it do mapping and binding between IP address, MAC address and public keys of the nodes in the node's neighbors cache, intruders will not be able to spoof other nodes' IP addresses.
机译:Internet协议版本4(IPv4)将逐渐被Internet协议版本6(IPv6)取代,作为下一代Internet协议。邻居发现协议(NDP)是IPv6套件中的主要协议之一,包括用于IPv6的邻居发现。主机和路由器都使用NDP。它的功能包括邻居发现(ND),路由器发现(RD),地址自动配置,地址解析,邻居不可达性检测(NUD),重复地址检测(DAD)和重定向。如果没有安全保护,则NDP容易受到各种攻击:邻居请求(NS)欺骗和邻居广告(NS)欺骗,重定向,窃取地址,拒绝服务就是这些攻击的示例。由于NDP在设计和开发的早期阶段就假定节点之间的连接将是安全的,但是部署阶段证明此假设是不正确的,并突出了安全漏洞。这一事实导致Internet工程师任务组(IETF)要求解决方案,以克服这些缺点。然后提出了SECure Neighbor Discovery或SEND,SEND解决了与NDP相关的部分威胁,并要求进行更多的研究,以找到更好的解决方案来设法禁止所有这些威胁并忽略其局限性。这项研究提出了一种新的机制,可以基于数字签名过程来避免IPv6 NDP的安全威胁。所提出的解决方案设法消除了威胁,因为它可以在节点的邻居缓存中的节点的IP地址,MAC地址和公钥之间进行映射和绑定,入侵者将无法欺骗其他节点的IP地址。

著录项

  • 来源
    《American journal of applied sciences》 |2014年第9期|1472-1479|共8页
  • 作者单位

    Research Center for Software Technology and Management, Network and Communication Technology Lab, Faculty of Information Science and Technology, Universiti Kebangsaan Malaysia, 43600 UKM Bangi, Selangor, Malaysia;

    Research Center for Software Technology and Management, Network and Communication Technology Lab, Faculty of Information Science and Technology, Universiti Kebangsaan Malaysia, 43600 UKM Bangi, Selangor, Malaysia;

    Research Center for Software Technology and Management, Network and Communication Technology Lab, Faculty of Information Science and Technology, Universiti Kebangsaan Malaysia, 43600 UKM Bangi, Selangor, Malaysia;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    IPv6; NDP; NS; NA; Digital Signature;

    机译:IPv6;NDP;NS;和;电子签名;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号