DHCPAuth — A DHCP message authentication module

D. Dinu, Mihai Togan
{"title":"DHCPAuth — A DHCP message authentication module","authors":"D. Dinu, Mihai Togan","doi":"10.1109/SACI.2015.7208238","DOIUrl":null,"url":null,"abstract":"DHCP is one of the most used network protocols, despite the security issues it has. Our work is motivated by the numerous attacks that can be launched against DHCP and the impact that they can have. Firstly, we formulate the constraints and design principles for a DHCP message authentication module that is flexible and easy to integrate with current DHCP implementations, while providing the necessary level of security. Then we present DHCPAuth, a module for authenticating DHCP messages. The module uses the RFC 3118 authentication option format and is able to authenticate DHCP client and server messages using two trust models: PKI and PGP. The proposed module is evaluated using different public key pairs in the considered trust models to determine the overhead introduced and the impact on DHCP operation. Results show the additional time required to process the DHCP messages, either when signing or verifying the signatures, as well as the authentication option length and the DHCP packet length. We also provide an analysis of worse case time for verifying the authentication option when more certificates or public keys are available on certificate store or public key ring. These information can help network administrators in selecting the trust model, the key types and sizes to use.","PeriodicalId":312683,"journal":{"name":"2015 IEEE 10th Jubilee International Symposium on Applied Computational Intelligence and Informatics","volume":"257 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2015-05-21","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"7","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2015 IEEE 10th Jubilee International Symposium on Applied Computational Intelligence and Informatics","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/SACI.2015.7208238","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 7

Abstract

DHCP is one of the most used network protocols, despite the security issues it has. Our work is motivated by the numerous attacks that can be launched against DHCP and the impact that they can have. Firstly, we formulate the constraints and design principles for a DHCP message authentication module that is flexible and easy to integrate with current DHCP implementations, while providing the necessary level of security. Then we present DHCPAuth, a module for authenticating DHCP messages. The module uses the RFC 3118 authentication option format and is able to authenticate DHCP client and server messages using two trust models: PKI and PGP. The proposed module is evaluated using different public key pairs in the considered trust models to determine the overhead introduced and the impact on DHCP operation. Results show the additional time required to process the DHCP messages, either when signing or verifying the signatures, as well as the authentication option length and the DHCP packet length. We also provide an analysis of worse case time for verifying the authentication option when more certificates or public keys are available on certificate store or public key ring. These information can help network administrators in selecting the trust model, the key types and sizes to use.
DHCPAuth—DHCP报文认证模块
DHCP是最常用的网络协议之一,尽管它有安全问题。我们工作的动机是针对DHCP发起的众多攻击及其可能产生的影响。首先,我们提出了DHCP消息认证模块的约束和设计原则,该模块具有灵活性,易于与现有DHCP实现集成,同时提供必要的安全级别。然后介绍了一个验证DHCP消息的模块DHCPAuth。该模块使用RFC 3118认证选项格式,能够使用PKI和PGP两种信任模型对DHCP客户端和服务器消息进行认证。使用所考虑的信任模型中的不同公钥对评估所建议的模块,以确定引入的开销和对DHCP操作的影响。结果显示了在签名或验证签名时处理DHCP消息所需的额外时间,以及身份验证选项长度和DHCP数据包长度。我们还分析了当证书存储库或公钥环上有更多证书或公钥可用时验证身份验证选项的最坏情况所需的时间。这些信息可以帮助网络管理员选择要使用的信任模型、密钥类型和大小。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信