Towards a Secure IPv6 Autoconfiguration
Junaid Latief Shah, Heena Farooq Bhat · Information Security Journal A Global Perspective · 2020
Stateless Address Autoconfiguration (SLAAC) is one of the novel features introduced in IPv6 Neighbor Discovery Protocol (NDP) providing for self-configuration of nodes and supplementing the reduction of operational and deployment cost of networks. Although self-configuration elevates the idea of autonomy for network, it has also introduced vulnerabilities that require substantial solutions. The SLAAC is pivoted on the presumption that network consists of authentic and entrusted nodes, however with inception of public sector wireless networks; any node can affix to the link with trivial authentication and situation changes radically. Although some security extensions like IPsec or SeND have been proposed, but these security protocols have been reported to have serious limitations like complex cryptographic algorithms which negate their adoption. This paper revisits the stateless auto configuration process and discusses its inherent vulnerabilities. The paper surveys existing research and available defense mechanisms available to protect SLAAC. The paper also suggests some guidelines from existing literature which can further promote and supplement the research to secure the auto configuration process. Finally, a novel technique is proposed for securing IPv6 link layer communication against DoS and Man-in-the-Middle attack which can be used as an alternate approach for CGA and SeND protocol.