DocumentCode :
2748061
Title :
Protecting teredo clients from source routing exploits
Author :
Al-tamimi, B.N.A. ; Taib, Abidah Mat ; Budiarto, Rahmat
Author_Institution :
NAV6 Centre, Univ. Sains Malaysia, Minden
fYear :
2008
fDate :
21-22 Oct. 2008
Firstpage :
126
Lastpage :
133
Abstract :
Tunneling techniques such as configured tunnel, 6to4, ISATAP and Teredo are common mechanisms in the early deployment of IPv6 to connect between two isolated IPv6 LANs or hosts by using the IPv4 infrastructure. We focused on Teredo tunnel as it allows users behind NATs to obtain IPv6 connectivity. Teredo tunnel has been designed to encapsulate IPv6 packet in UDP using IPv6-in-UDPin-IPv4 technology. Though, Teredo tunnel raised some security threats including source routing exploits. This paper describes source routing exploits at the Teredo client and proposes a Teredo Client Protection Algorithm (TCPA) as an alternative mechanism to protect Teredo clients from IPv6 routing header risks. Since source routing in the IPv6 header could be exploited by either external or internal attackers, we believed our TCPA algorithm plays an impact in preventing potential attacks. TCPA is based on the filtration principle of matching. It operates on the Teredo client to deny the IPv6 packets which have routing header addresses unless the user allows these addresses traverse through it. The TCPA was implemented as a simulation in a real environment and the results showed that the proposed method is efficient and its logic sounds enough to protect Teredo client from attackers.
Keywords :
Internet; routing protocols; telecommunication security; transport protocols; IPv6-in-UDP-in-IPv4 technology; Teredo client protection algorithm; Teredo tunnel; security threats; source routing exploits; Data security; Filtration; IP networks; Isolation technology; Logic; Network address translation; Protection; Protocols; Routing; Tunneling; IPv6; Routing header; Teredo Client Protection Algorithm (TCPA); Teredo tunnel;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Distributed Framework and Applications, 2008. DFmA 2008. First International Conference on
Conference_Location :
Penang
Print_ISBN :
978-1-4244-2312-5
Electronic_ISBN :
978-1-4244-2313-2
Type :
conf
DOI :
10.1109/ICDFMA.2008.4784425
Filename :
4784425
Link To Document :
بازگشت