计算机应用 ›› 2014, Vol. 34 ›› Issue (4): 950-954.DOI: 10.11772/j.issn.1001-9081.2014.04.0950

• 网络与通信 • 上一篇    下一篇

基于改进反向探测的IPv6邻居缓存保护方法

孔亚洲,王振兴,王禹,张连成   

  1. 数学工程与先进计算国家重点实验室,郑州 450002
  • 收稿日期:2013-10-14 修回日期:2013-12-19 出版日期:2014-04-01 发布日期:2014-04-29
  • 通讯作者: 孔亚洲
  • 作者简介:孔亚洲(1989-),男,河南濮阳人,硕士研究生,CCF会员,主要研究方向:IPv6网络安全;
    王振兴(1959-),男,河北晋州人,教授,博士,主要研究方向:IPv6网络安全;
    王禹(1984-),男,河南郑州人,博士研究生,主要研究方向:网络安全;
    张连成(1982-),男,河南商丘人,讲师,博士,主要研究方向:流量分析、网络安全。

Method of IPv6 neighbor cache protection based on improved reversed detection

KONG Yazhou,WANG Zhenxing,WANG Yu,ZHANG Liancheng   

  1. State Key Laboratory of Mathematical Engineering and Advanced Computing, Zhengzhou Henan 450002, China
  • Received:2013-10-14 Revised:2013-12-19 Online:2014-04-01 Published:2014-04-29
  • Contact: KONG Yazhou

摘要:

针对IPv6邻居缓存(NC)易被攻击的问题,提出一种改进的反向探测方法(RD+)。该方法首先引入时间戳和报文序列两个选项,分别用于限制报文响应时长以及响应报文匹配;之后,定义RD+队列存储时间戳和报文序号等信息,并设计基于时间戳的随机早期检测(RED-T)算法对RD+队列实施管理以防范拒绝服务(DoS)攻击。实验结果表明,RD+能够有效抵抗邻居缓存欺骗和DoS攻击,与启发式和显式相结合的方法(HE)以及安全邻居发现协议(SEND)相比,其资源消耗较少。

Abstract:

IPv6 Neighbor Cache (NC) was very vulnerable to be attacked, therefore, an improved method named Reversed Detection Plus (RD+) was proposed. Timestamp and sequence were firstly introduced to limit strict time of response and response matching respectively; RD+ queue was defined to store timestamp and sequence, and Random Early Detection Based on Timestamp (RED-T) algorithm was designed to prevent Denial of Service (DoS) attacks. The experimental results show that RD+ can effectively protect IPv6 NC to resist spoofing and DoS attacks, and compared with Heuristic and Explicit (HE) and Secure Neighbor Discovery (SEND), RD+ has a low consumption of resources.

中图分类号: