Title
Real-Time IP Checking and Packet Marking for Preventing ND-DoS Attack Employing Fake Source IP in IPv6 LAN
Abstract
IPv6 has been proposed as a basic Internet protocol for realizing a ubiquitous computing service. An IPv6 LAN may suffer from a Neighbor Discovery-Denial of Service (ND-DoS) attack, which results in network congestion on the victim IPv6 LAN by making a great number of Neighbor Discovery protocol messages generated. A ND-DoS attacker may use a fake source IP address to hide his/her identity, which makes it more difficult to handle the attack. In this paper, we propose an IP checking and packet marking scheme, which is applied to an IPv6 access router. The proposed scheme can effectively protect IPv6 LAN from ND-DoS attack employing fake source IP by providing the packets suspected to use fake source and/or destination IP addresses with a poor QoS.
Year
DOI
Venue
2008
10.1007/978-3-540-69295-9_5
ATC
Keywords
Field
DocType
destination ip address,nd-dos attacker,ip checking,packet marking,ipv6 lan,fake source ip address,fake source,fake source ip,preventing nd-dos attack employing,victim ipv6 lan,real-time ip checking,ipv6 access router,nd-dos attack,dos attack,neighbor discovery,ubiquitous computing,real time,internet protocol,network congestion,denial of service
Internet Protocol,Denial-of-service attack,Packet drop attack,Computer security,Computer science,Computer network,Smurf attack,IP address management,Loose Source Routing,Neighbor Discovery Protocol,IP tunnel
Conference
Volume
ISSN
Citations 
5060
0302-9743
1
PageRank 
References 
Authors
0.35
12
2
Name
Order
Citations
PageRank
Gaeil An1123.02
Kiyoung Kim242.50