Dergiler / INTERNATIONAL JOURNAL OF INFORMATION SECURITY SCIENCE / 2020 / Cilt: 9 - Sayı: 1
SLAAC Attack Detection Mechanism
- Sayfa
- 24–43
- DOI
- —
Özet
Attacks against Neighbour Discovery Protocol (NDP) is a major security issue in Internet Protocol Version 6 (IPv6). It demands security expert attention because the availability of attacking toolkits has amplified the risk of NDP attack in IPv6 network. Stateless Address Autoconfiguration (SLAAC) attack is a type of NDP attack exploited by attacker to launch MiTM and DoS attack. Researcher have proposed IPSec, Secure NDP (SeND), SAVI, RA-Guard, Trust-ND and other methods but have not been implemented widely due to enormous resources requirement for cryptographic process and alteration of original NDP. This paper proposes a detection mechanism named SADetection to detect SLAAC attack. SADetection incorporated enhanced ongoing packet verification and authentication mechanism. SADetection has been implemented in testbed and has detected three (3) variants of SLAAC attack which are attack using ICMPv6 packet, using fragment packet and using packet with extension header. SADetection has been found to be lightweight, platform-independence and interoperable. SADetection does not alter original NDP thus resource practical to SLAAC attack