An Improved Secure Router Discovery Mechanism to Prevent Fake RA Attack in Link Local IPv6 Network

Navaneethan C. Arjuman, Selvakumar Manickam, Shankar Karuppayah · Communications in computer and information science · 2021

In Stateless Address Auto Configuration (SLAAC) in the IPv6 network, the host obtain the network prefix using Router Discovery (RD) protocol. The standard RD by design do not have trust mechanism to authenticate the legitimate host and router. This design flaw within RD protocol has led to Fake Router Advertisement (Fake RA) attack where the host is denied of the legitimate gateway. In order to address this issue, several prevention techniques such as Trust Neighbour Discovery (Trust-ND), CGA + Internet Protocol Security (IPSec) Authentication Header (AH) NDP mechanism and others have been proposed in the past. However, these techniques also face other vulnerabilities such as high computation cost, hash collision attacks and bootstrapping problem. Hence, this paper review shortcoming of these mechanisms and proposes an improved secure RD mechanism i.e. the SecMac-Secure Router Discovery (SecMac-SRD) mechanism to overcome the Fake RA attacks. SecMac-SRD mechanism provides 60.8% reduction of processing time compare to Trust-ND while preventing Fake RA attacks during the RD process in the link local communication of the IPv6 network.

Read the paper · More papers on PaperTik