<p>The explosive growth of internet users and the limitations of IPv4 necessitated a transition to IPv6, offering a vast address space and advanced functionalities. A critical component of IPv6 is Stateless Address Auto-Configuration (SLAAC), where devices automatically configure their network addresses. Integral to SLAAC is the Duplicate Address Detection (DAD) process, which ensures each IP address is unique by detecting and resolving conflicts. However, traditional DAD remains vulnerable to spoofing and denial-of-service (DoS) attacks due to the lack of authentication, allowing malicious nodes to block address assignment. This paper proposes an enhanced DAD algorithm that conceals the tentative address using a cryptographic hash and separates its components across Neighbor Solicitation (NS) and Neighbor Advertisement (NA) messages, preventing attackers from learning the complete value. We evaluate the proposed method against Standard DAD and an existing secure DAD under both normal and attack scenarios. Results show that our approach reduces DoS success probability from 100% (Standard DAD) to approximately <InlineEquation ID="IEq1"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="42979_2025_4448_Article_IEq1.gif" Format="GIF" Height="17" Rendition="HTML" Resolution="72" Type="Linedraw" Width="80" /> </InlineMediaObject> <EquationSource Format="TEX">\(8.8\times 10^{-36}\)</EquationSource> </InlineEquation>, while also lowering packet overhead under attack, reducing network overhead, and maintaining stable CPU and memory usage. This balance of security and efficiency demonstrates that the proposed DAD mechanism not only resists spoofing and DoS attacks but also preserves practical deployability in IPv6 networks.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A Privacy Preserving Mechanism for Securing IPv6 Duplicate Address Detection Against DoS Attacks

  • Amar Kumar Yadav,
  • Ravichandra Sadam

摘要

The explosive growth of internet users and the limitations of IPv4 necessitated a transition to IPv6, offering a vast address space and advanced functionalities. A critical component of IPv6 is Stateless Address Auto-Configuration (SLAAC), where devices automatically configure their network addresses. Integral to SLAAC is the Duplicate Address Detection (DAD) process, which ensures each IP address is unique by detecting and resolving conflicts. However, traditional DAD remains vulnerable to spoofing and denial-of-service (DoS) attacks due to the lack of authentication, allowing malicious nodes to block address assignment. This paper proposes an enhanced DAD algorithm that conceals the tentative address using a cryptographic hash and separates its components across Neighbor Solicitation (NS) and Neighbor Advertisement (NA) messages, preventing attackers from learning the complete value. We evaluate the proposed method against Standard DAD and an existing secure DAD under both normal and attack scenarios. Results show that our approach reduces DoS success probability from 100% (Standard DAD) to approximately \(8.8\times 10^{-36}\) , while also lowering packet overhead under attack, reducing network overhead, and maintaining stable CPU and memory usage. This balance of security and efficiency demonstrates that the proposed DAD mechanism not only resists spoofing and DoS attacks but also preserves practical deployability in IPv6 networks.