重复地址检测过程中抗DoS攻击的有效CGA算法

Cui Zhang, Jinbo Xiong, Qiong Wu
{"title":"重复地址检测过程中抗DoS攻击的有效CGA算法","authors":"Cui Zhang, Jinbo Xiong, Qiong Wu","doi":"10.1109/WCNCW.2016.7552745","DOIUrl":null,"url":null,"abstract":"Neighbor Discovery Protocol (NDP) is significant in mobile network, which enables mobile node randomly access to foreign network by Stateless Link Address Autoconfiguration (SLAAC). However, the NDP initially offers no protection mechanism and is prone to address spoofing and Denial of Service (DoS). Secure Neighbor Discovery Protocol (SeNDP) is proposed to solve these NDP threats. Recently there are many solutions presented in SeNDP which relies on special IPv6 addresses named Cryptographically Generated Address (CGA). But there is little work to defend DoS attack on Duplicate Address Detection (DAD). In our paper, we focus on the problems of CGA and propose a novel time-based monitoring DoS attack. The conventional DoS defense mechanisms are realized by monitoring the packet rating and observing connection delay to analyze various DoS attack. Hence, we adopt a delay as an indication to distinct the DoS attack. We set a timer to control the address generation for monitoring abnormal attack to protect each address configuration. In addition, we adopt SHA-224 hash function instead of SHA-1 to improve the security of address generation. Considering the computation overhead, we decrease the hash matching factor from 16 bits to 8 bits. We develop our scheme using the Network Simulator (NS2) and the OpenSSL library. Finally, experiment results prove our scheme can provide more efficient IP generation. Compared with the CGA algorithm in SeNDP, our time consumption decreases to 10%. From the view of defense attack, our scheme can control DoS attack.","PeriodicalId":436094,"journal":{"name":"2016 IEEE Wireless Communications and Networking Conference Workshops (WCNCW)","volume":"31 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"1900-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":"{\"title\":\"An efficient CGA algorithm against DoS attack on Duplicate Address Detection process\",\"authors\":\"Cui Zhang, Jinbo Xiong, Qiong Wu\",\"doi\":\"10.1109/WCNCW.2016.7552745\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Neighbor Discovery Protocol (NDP) is significant in mobile network, which enables mobile node randomly access to foreign network by Stateless Link Address Autoconfiguration (SLAAC). However, the NDP initially offers no protection mechanism and is prone to address spoofing and Denial of Service (DoS). Secure Neighbor Discovery Protocol (SeNDP) is proposed to solve these NDP threats. Recently there are many solutions presented in SeNDP which relies on special IPv6 addresses named Cryptographically Generated Address (CGA). But there is little work to defend DoS attack on Duplicate Address Detection (DAD). In our paper, we focus on the problems of CGA and propose a novel time-based monitoring DoS attack. The conventional DoS defense mechanisms are realized by monitoring the packet rating and observing connection delay to analyze various DoS attack. Hence, we adopt a delay as an indication to distinct the DoS attack. We set a timer to control the address generation for monitoring abnormal attack to protect each address configuration. In addition, we adopt SHA-224 hash function instead of SHA-1 to improve the security of address generation. Considering the computation overhead, we decrease the hash matching factor from 16 bits to 8 bits. We develop our scheme using the Network Simulator (NS2) and the OpenSSL library. Finally, experiment results prove our scheme can provide more efficient IP generation. Compared with the CGA algorithm in SeNDP, our time consumption decreases to 10%. From the view of defense attack, our scheme can control DoS attack.\",\"PeriodicalId\":436094,\"journal\":{\"name\":\"2016 IEEE Wireless Communications and Networking Conference Workshops (WCNCW)\",\"volume\":\"31 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"1900-01-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"2\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2016 IEEE Wireless Communications and Networking Conference Workshops (WCNCW)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/WCNCW.2016.7552745\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2016 IEEE Wireless Communications and Networking Conference Workshops (WCNCW)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/WCNCW.2016.7552745","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2

摘要

邻居发现协议(NDP)在移动网络中具有重要意义,它通过无状态链路地址自动配置(SLAAC)实现移动节点随机访问外部网络。但是,NDP在初始阶段没有提供任何保护机制,容易受到欺骗和拒绝服务(DoS)攻击。为了解决这些威胁,提出了安全邻居发现协议(SeNDP)。最近在SeNDP中提出了许多基于特殊IPv6地址的解决方案,这些地址被称为加密生成地址(cryptographic Generated Address, CGA)。但是对于重复地址检测(DAD)的DoS攻击的防御工作却很少。本文针对CGA存在的问题,提出了一种基于时间的监控DoS攻击方法。传统的DoS防御机制是通过监测数据包评级和观察连接延迟来分析各种DoS攻击。因此,我们采用延迟作为区分DoS攻击的指示。通过设置定时器控制地址生成,监控异常攻击,保护每个地址配置。此外,我们采用SHA-224哈希函数代替SHA-1来提高地址生成的安全性。考虑到计算开销,我们将哈希匹配因子从16位减少到8位。我们使用网络模拟器(NS2)和OpenSSL库来开发我们的方案。实验结果表明,该方案能够提供更高效的IP生成。与SeNDP中的CGA算法相比,我们的时间消耗降低到10%。从防御攻击的角度来看,我们的方案可以控制DoS攻击。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
An efficient CGA algorithm against DoS attack on Duplicate Address Detection process
Neighbor Discovery Protocol (NDP) is significant in mobile network, which enables mobile node randomly access to foreign network by Stateless Link Address Autoconfiguration (SLAAC). However, the NDP initially offers no protection mechanism and is prone to address spoofing and Denial of Service (DoS). Secure Neighbor Discovery Protocol (SeNDP) is proposed to solve these NDP threats. Recently there are many solutions presented in SeNDP which relies on special IPv6 addresses named Cryptographically Generated Address (CGA). But there is little work to defend DoS attack on Duplicate Address Detection (DAD). In our paper, we focus on the problems of CGA and propose a novel time-based monitoring DoS attack. The conventional DoS defense mechanisms are realized by monitoring the packet rating and observing connection delay to analyze various DoS attack. Hence, we adopt a delay as an indication to distinct the DoS attack. We set a timer to control the address generation for monitoring abnormal attack to protect each address configuration. In addition, we adopt SHA-224 hash function instead of SHA-1 to improve the security of address generation. Considering the computation overhead, we decrease the hash matching factor from 16 bits to 8 bits. We develop our scheme using the Network Simulator (NS2) and the OpenSSL library. Finally, experiment results prove our scheme can provide more efficient IP generation. Compared with the CGA algorithm in SeNDP, our time consumption decreases to 10%. From the view of defense attack, our scheme can control DoS attack.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信