ETRI-Knowledge Sharing Plaform

KOREAN
논문 검색
Type SCI
Year ~ Keyword

Detail

Conference Paper Real-Time IP Checking and Packet Marking for Preventing ND-DoS Attack Employing Fake Source IP in IPv6 LAN
Cited 4 time in scopus Download 0 time Share share facebook twitter linkedin kakaostory
Authors
Gae Il An, Ki Young Kim
Issue Date
2008-06
Citation
International Conference on Autonomic and Trusted Computing (ATC) 2008 (LNCS 5060), v.5060, pp.36-46
Language
English
Type
Conference Paper
DOI
https://dx.doi.org/10.1007/978-3-540-69295-9_5
Project Code
08MS2400, Development of the threat containment for all-in-one mobile devices on convergence networks, Kim Ki Young
Abstract
IPv6 has been proposed as a basic Internet protocol for realizing a ubiquitous computing service. An IPv6 LAN may suffer from a Neighbor Discovery-Denial of Service (ND-DoS) attack, which results in network congestion on the victim IPv6 LAN by making a great number of Neighbor Discovery protocol messages generated. A ND-DoS attacker may use a fake source IP address to hide his/her identity, which makes it more difficult to handle the attack. In this paper, we propose an IP checking and packet marking scheme, which is applied to an IPv6 access router. The proposed scheme can effectively protect IPv6 LAN from ND-DoS attack employing fake source IP by providing the packets suspected to use fake source and/or destination IP addresses with a poor QoS. © 2008 Springer-Verlag Berlin Heidelberg.
KSP Keywords
Access router, DoS Attacks, Fake Source, IP address, Internet protocol(IP), Neighbor Discovery Protocol, Network Congestion, Real-Time, denial of service(DoS), packet marking, ubiquitous computing