透過您的圖書館登入
IP:3.15.31.206
  • 期刊

適用於IPv6無線網路芳鄰探索攻擊的防禦系統

A Defensive System against Neighbor Discovery Attacks in IPv6 Wireless Networks

若您是本文的作者,可授權文章由華藝線上圖書館中協助推廣。

摘要


在IPv6網路中,相同連結上的各個節點利用芳鄰探索(neighbor discovery, ND)協定來確定相鄰節點之間的關係(如確定對方是否存在、解析對方的連結層位址等)及進行基本的網路組態配置。在沒有確保連結上的節點都是可信任的情形下,此協定容易遭受惡意僞造封包的威脅,尤其在無線的網路環境下,此威脅更加難以防範。雖然IETF提出了SEcure Neighbor Discovery (SEND)協定來保護芳鄰探索訊息的安全,但驗證過程需要花時間及系統資源,對於一般輕型的無線網路的裝置,造成了不小的負擔。 在本文中,我們提出一個避免IPv6無線網路下芳鄰探索機制被攻擊且適用於輕型無線裝置的防禦系統。藉由IPv6節點取得合法IP位址時,會先經重複位址偵測(duplicate address detection, DAD)程序來確保位址唯一的特性,本系統透過分析DAD訊息封包及追蹤使用者連線狀態的方式,來阻檔偽造芳鄰探索封包的攻擊。我們利用HostAP軟體作爲無線基地台,並修改HostAP軟體核心,將防禦功能植入。實驗結果顯示我們所提出系統的效能,足讓一般輕型的無線裝置皆適用於本防禦系統。

並列摘要


In IPv6 networks, Neighbor Discovery Protocol (NDP) is usually used to determine the relationship (e.g., the current accessibility or the link-layer address of a neighboring node) between nodes on the same link and to configure the network interface. This protocol is vulnerable to threats from spoofing packets due to the lack of a mutual trust mechanism among the communication nodes, especially in wireless environments. Therefore, the IETF has proposed the Secure Neighbor Discovery (SEND) protocol to safeguard Neighbor Discovery messages. Currently, common lightweight wireless network devices tend to reduce resource consumption, thereby conflicting with heavyweight SEND message computational requirements. In this research, a defensive system against Neighbor Discovery (ND) attacks on lightweight devices in IPv6 wireless networks is proposed. In an IPv6 network, as a node prepares to assume a new address for its own use, it must first verify that no other node on the link uses that particular address. This procedure is accomplished by the Duplicate Address Detection (DAD) process. By implementing this feature, through an analysis of DAD packets and tracing the user’s linking status, spoofing ND packets can be effectively blocked. In the proposed system, a HostAP was adopted to provide access-point functions. Thus, we modified the kernel of the HostAP for embedding the defense functions. The experimental results revealed that the proposed system is both applicable to and appropriate for the network security of lightweight wireless devices operating in IPv6 wireless networks.

延伸閱讀