CGA Configuration Detection Method of IPv6 Nodes by Combining Active Probing with Passive Sniffing

Liancheng Zhang, Jianping Sun, Juwei Yan, Yi Guo, Lanxin Cheng, Wenwen Du
{"title":"CGA Configuration Detection Method of IPv6 Nodes by Combining Active Probing with Passive Sniffing","authors":"Liancheng Zhang, Jianping Sun, Juwei Yan, Yi Guo, Lanxin Cheng, Wenwen Du","doi":"10.1109/ICCT56141.2022.10072432","DOIUrl":null,"url":null,"abstract":"To ensure the security of neighbor discovery messages and processes, IPv6 subnets are increasingly deploying secure neighbor discovery (SEND) mechanisms. Although the cryptographically generated address (CGA) mechanism is the operating basis of the SEND mechanism, there is currently no technology or method for CGA configuration detection. To this end, the difficult problems lacking of CGA configuration detection method (such as the constraints caused by built-in neighbor discovery mechanism, identification of different SEND transition scenes, IPv6 address transformation) are analyzed through the in-depth analysis of the SEND mechanism and the CGA mechanism. Moreover, a CGA configuration detection method of IPv6 nodes by combining active probing and passive sniffing (CCD6-APPS) is proposed. Based on active probing and passive sniffing of active IPv6 nodes in the target IPv6 subnet, the proposed CCD6-APPS method can learn the SEND implementation methods and CGA configuration parameters of IPv6 nodes, and finally detect the coverage of SEND nodes in the target IPv6 subnet. By setting up a typical IPv6 neighbor discovery experimental environment and conducting targeted tests, the experimental results prove the effectiveness of the SSD6-APPS method, and the additional impact on the target IPv6 subnet is very small.","PeriodicalId":294057,"journal":{"name":"2022 IEEE 22nd International Conference on Communication Technology (ICCT)","volume":"99 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2022-11-11","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2022 IEEE 22nd International Conference on Communication Technology (ICCT)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICCT56141.2022.10072432","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

To ensure the security of neighbor discovery messages and processes, IPv6 subnets are increasingly deploying secure neighbor discovery (SEND) mechanisms. Although the cryptographically generated address (CGA) mechanism is the operating basis of the SEND mechanism, there is currently no technology or method for CGA configuration detection. To this end, the difficult problems lacking of CGA configuration detection method (such as the constraints caused by built-in neighbor discovery mechanism, identification of different SEND transition scenes, IPv6 address transformation) are analyzed through the in-depth analysis of the SEND mechanism and the CGA mechanism. Moreover, a CGA configuration detection method of IPv6 nodes by combining active probing and passive sniffing (CCD6-APPS) is proposed. Based on active probing and passive sniffing of active IPv6 nodes in the target IPv6 subnet, the proposed CCD6-APPS method can learn the SEND implementation methods and CGA configuration parameters of IPv6 nodes, and finally detect the coverage of SEND nodes in the target IPv6 subnet. By setting up a typical IPv6 neighbor discovery experimental environment and conducting targeted tests, the experimental results prove the effectiveness of the SSD6-APPS method, and the additional impact on the target IPv6 subnet is very small.
主动探测与被动探测相结合的IPv6节点CGA配置检测方法
为了保证邻居发现消息和进程的安全,IPv6子网中越来越多地部署了SEND (secure neighbor discovery)机制。虽然加密生成地址(cryptographic generated address, CGA)机制是SEND机制的运行基础,但是目前还没有CGA配置检测的技术和方法。为此,通过对SEND机制和CGA机制的深入分析,分析了CGA配置检测方法缺乏的难点问题(如内置邻居发现机制带来的约束、不同SEND转换场景的识别、IPv6地址转换等)。提出了一种主动探测与被动嗅探相结合的IPv6节点CGA配置检测方法(CCD6-APPS)。本文提出的CCD6-APPS方法通过对目标IPv6子网内的主动IPv6节点进行主动探测和被动嗅探,学习IPv6节点的SEND实现方法和CGA配置参数,最终检测目标IPv6子网内SEND节点的覆盖情况。通过搭建一个典型的IPv6邻居发现实验环境并进行针对性的测试,实验结果证明了SSD6-APPS方法的有效性,并且对目标IPv6子网的附加影响很小。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信