Telecommunications Science ›› 2014, Vol. 30 ›› Issue (4): 54-60.doi: 10.3969/j.issn.1000-0801.2014.04.008

• Research And Development • Previous Articles     Next Articles

A Defense Approach of DAD Attack in Stateless Auto Configuration

Guangjia Song1,Zhenzhou Ji1,Hui Wang2   

  1. 1 School of Computer Science and Technology, Harbin Institute of Technology, Harbin 150001, China
    2 National Computer Network Emergency Response Technical Team/Coordination Center of China, Beijing 100029, China
  • Online:2014-04-15 Published:2017-06-29

Abstract:

In stateless address auto configuration, node needs to carry out duplicate address detection before using a new IP address. In the detection process, once a malicious node claims that the resolve IP address is occupied, the node's address configuration will fail. For this case, WAY(who are you)mechanism as a defensive approach was proposed. WAY mechanism uses reverse address confirmation, self-declaration and WAY-table inspection to filter the spoofing packets, which make attackers' cost increase and cannot carry out secondary attack. The experiments show that WAY mechanism can effectively compensate the security flaws of neighbor discovery protocol, significantly increase the success rate of stateless address auto configuration.

Key words: network security, address resolution, IPv6, stateless address auto configuration, duplicate address detection

No Suggested Reading articles found!