摘要
To secure the operations of address auto-configuration protocols in IPv6 networks, a solution called Secure Address Configuration for IPv6 (SAC6) is proposed in this paper. Unlike the previous solutions that mainly use the cryptographic approach, SAC6 eliminates the threats to configuration protocols for the network nodes by acting like a Neighbor Discovery Protocol agent. The major merit of SAC6 is that its operations are transparent to the network and do not require the modification of existing protocols. Therefore, it can be seamlessly deployed in existing IPv6 networks. To demonstrate the viability of SAC6, we implemented SAC6 as a kernel module in a Linux bridge. In our experiments, SAC6 have successfully blocked various kinds of spoofing configuration protocol messages and prevent the network nodes from being attacked during the address configuration.
原文 | English |
---|---|
頁(從 - 到) | 551-558 |
頁數 | 8 |
期刊 | Journal of Internet Technology |
卷 | 13 |
發行號 | 4 |
出版狀態 | Published - 2012 |