DocumentCode
1828212
Title
Compact neighbor discovery: a bandwidth defense through bandwidth optimization
Author
Mutaf, Pars ; Castelluccia, Claude
Author_Institution
INRIA, France
Volume
4
fYear
2005
fDate
13-17 March 2005
Firstpage
2711
Abstract
We present a stateless defense against the neighbor discovery denial-of-service (ND-DoS) attack in IPv6. The ND-DoS attack consists of remotely flooding a target subnet with bogus packets destined for random interface identifiers; a different one for each malicious packet. The 128-bit IPv6 address reserves its 64 low-order bits for the interface ID. Consequently, the malicious packets are very likely to fall on previously unresolved addresses and the target access router (or leaf router) is obligated to resolve these addresses by sending neighbor solicitation packets. Neighbor solicitation packets are link layer multicast (or broadcast), and hence also forwarded by bridges. As a consequence, the attack may consume important bandwidth in subnets with wireless bridges, or access points. This problem is particularly important in the presence of mobile IPv6 devices that expect incoming sessions from the Internet. In this case, address resolution is crucial for the access router to reliably deliver incoming sessions to idle mobile devices with unknown MAC addresses. We propose a novel neighbor solicitation technique using Bloom filters. Multiple IPv6 addresses (bogus or real) that are waiting in the access router´s address resolution queue are compactly represented using a Bloom filter. By broadcasting a single neighbor solicitation message that carries the Bloom filter, multiple IPv6 addresses are concurrently solicited. Legitimate neighbor solicitation triggering packets are not denied service. An on-link host can detect its address in the received Bloom filter and return its MAC address to the access router. A bandwidth gain around 40 can be achieved in all cells of the target subnet. This approach that we call compact neighbor discovery (CND) is the first bandwidth DoS defense that we are aware of to employ a bandwidth optimization.
Keywords
IP networks; Internet; access protocols; computer network reliability; filtering theory; mobile radio; optimisation; quality of service; queueing theory; radio links; routing protocols; security of data; Bloom filters; CND; Internet; MAC address; ND-DoS; access point; address resolution; broadcasting; compact neighbor discovery; link layer multicast; mobile IPv6 device; neighbor discovery denial-of-service attack; optimization; queueing theory; random interface; reliability; solicitation packet; target access router; wireless bridge; Bandwidth; Bridges; Broadcasting; Computer crime; IP networks; Information filtering; Information filters; Internet; Neodymium; Routing;
fLanguage
English
Publisher
ieee
Conference_Titel
INFOCOM 2005. 24th Annual Joint Conference of the IEEE Computer and Communications Societies. Proceedings IEEE
ISSN
0743-166X
Print_ISBN
0-7803-8968-9
Type
conf
DOI
10.1109/INFCOM.2005.1498554
Filename
1498554
Link To Document