Improved Mechanism to Prevent Denial of Service Attack in IPv6 Duplicate Address Detection Process

Abstract

From the days of ARPANET, with slightly over two hundred connected hosts involving five organizations to a massive global, always-on network connecting hosts in the billions, the Internet has become as important as the need for electricity and water. Internet Protocol version 4 (IPv4) could not sustain the growth of the Internet. In ensuring the growth is not stunted, a new protocol, i.e. Internet Protocol version 6 (IPv6) was introduced that resolves the addressing issue IPv4 had. In addition, IPv6 was also laden with new features and capabilities. One of them being address auto-configuration. This feature allows hosts to self-configure without the need for additional services. Nevertheless, the design of IPv6 has led to several security shortcomings. Duplicate Address Detection (DAD) process required for auto-configuration is prone to Denial of Service (DoS) attack in which hosts are unable to configure themselves to join the network. Various mechanisms, SeND, SSAS, and the most recent being Trust-ND, have been introduced to address this issue. Although these mechanisms were able to circumvent DoS attack on DAD process, they have introduced various side effects, i.e. complexities and degradation of performance. This paper reviews the shortcomings of these mechanism and proposes a new mechanism, Secure-DAD, that addresses them. The performance comparison between Trust-ND and Secure-ND also showed that Secure-DAD is more promising with improvement in terms of processing time reduction of 45.1% compared to Trust-ND while preventing DoS attack in IPv6 DAD process.

Authors and Affiliations

Shafiq Ul Rehman, Selvakumar Manickam

Keywords

Related Articles

Web Service Testing Techniques: A Systematic Literature Review

These days continual demands on loosely coupled systems have web service gives basic necessities to deliver resolution that are adaptable and sufficient to be work at runtime for maintaining the high quality of the syste...

Financial Market Prediction using Google Trends

Financial decisions are among the most significant life-changing decisions that individuals make. There is a strong correlation between financial decision making and human behavior. In this research the relationship betw...

An Efficient Protocol using Fuzzy Logic and Grids with Two-Dimensional Techniques for Saving Energy in WSN

This work proposes an energy-saving protocol for wireless sensor networks (WSNs) using fuzzy logic and grids with two-dimensional techniques, namely, gravity and energy centers, to address the pressing issue of energy ef...

Multi Focus Image Fusion using Combined Median and Average Filter based Hybrid Stationary Wavelet Transform and Principal Component Analysis

Poor illumination, less background contrast and blurring effects makes the medical, satellite and camera images difficult to visualize. Image fusion plays the vital role to enhance image quality by resolving the above is...

Impact of Different Data Types on Classifier Performance of Random Forest, Naïve Bayes, and K-Nearest Neighbors Algorithms

This study aims to evaluate impact of three different data types (Text only, Numeric Only and Text + Numeric) on classifier performance (Random Forest, k-Nearest Neighbor (kNN) and Naïve Bayes (NB) algorithms). The class...

Download PDF file
  • EP ID EP249033
  • DOI 10.14569/IJACSA.2017.080209
  • Views 83
  • Downloads 0

How To Cite

Shafiq Ul Rehman, Selvakumar Manickam (2017). Improved Mechanism to Prevent Denial of Service Attack in IPv6 Duplicate Address Detection Process. International Journal of Advanced Computer Science & Applications, 8(2), 63-70. https://europub.co.uk/articles/-A-249033