A New Technique to Mitigate DHCPv6 Starvation Attack and Authenticate Clients using DUID

Asaduzzaman Jony, Muhammad Nazrul Islam · 2024

Dynamic Host Configuration Protocol for IPv6 (DHCPv6) is susceptible to DHCPv6 starvation attack due to the lack of authentication and security mechanisms. RSA authentication was proposed to secure DHCPv6 which increases the DHCPv6 packet size by adding certificate option. Moreover, suggested method generates digital signatures using SHA-1, which is vulnerable to hash collision attack. Cryptography encryption based DHCPv6 server was suggested which is very difficult to deploy since it takes longer to process DHCPv6 requests and consumes more hardware resources. Finally, MAC address whitelisting based DHCPv6 client authentication was introduced which can be easily evaded by MAC spoofing attacks. Therefore, the objective of this study is to propose a secured DHCPv6 server having multilayered security architecture to prevent starvation attack and authenticate clients before assigning IPv6 address. First, a thorough analysis of the DHCPv6 starvation attack was demonstrated that exhausts hardware resources of the DHCPv6 server and causes DHCPv6 service outages and network instability. Then, a DHCPv6 server was proposed that allows only a predetermined number of DHCPv6 requests per minute to prevent DHCPv6 starvation attack and also offered a robust client authentication technique using client’s MAC address and uniquely generated DHCP Unique Identifier (DUID) before allocating IPv6 address. Finally, the effectiveness of proposed DHCPv6 server was evaluated in EVE-NG network simulation environment and found that it successfully prevents DHCPv6 starvation attack and authenticate clients.

Read the paper · More papers on PaperTik