SURVEY: SECURING IPV6 NEIGHBOR DISCOVERY PROTOCOL

استبيان: تأمين بروتوكول اكتشاف الجيران في IPv6

  • rujms ojs
  • Mohammed Ghaleb M. Ageel, Eng Al-Razi University
  • Yosef A. Abdulmoghni, Eng Al-Razi University
  • Yahya Al-Ashmoery, Prof Al-Razi University
الكلمات المفتاحية: Neighbor Discovery Protocol (NDP), Address Resolution Protocol (ARP), - Internet Protocol version 6 (IPv6), Man in the Middle (MiTM), Denial of Service (DoS), Internet Control Message Protocol version 6 (ICMPv6), - NDP security, Secure Neighbor Discovery, Cryptographically Generated Addresses

الملخص

: IPv6 Neighbor Discovery Protocol (NDP) is essential to facilitate communication between local network nodes. However, NDP is vulnerable to various attacks that can disrupt network communication and facilitate malicious activities. This study attempts to identify the major security vulnerabilities to NDP and assess available methods to improve its security. We conducted a systematic literature review to analyze the benefits and limitations of mechanisms such as Cryptographically Generated Addresses (CGA), Secure Neighbor Discovery (SEND), and Attestation-based Neighbor Discovery. Our findings show that these mechanisms significantly reduce the impact of Neighbor Discovery attacks. We recommend an attack detection mechanism to address spoofing of Neighbor Solicitation (NS) and Neighbor Advertisement (NA) messages to improve NDP security in IPv6 networks. These insights can help network administrators and protocol designers implement effective defenses against NDP attacks, thereby enhancing the stability and security of IPv6 deployments. Our research contributes to ongoing efforts to improve IPv6 network reliability by investigating the protocol's structure, the role of ICMPv6, associated security concerns, and potential security solutions.

السير الشخصية للمؤلفين

Mohammed Ghaleb M. Ageel, Eng، Al-Razi University

Mohammed Ghaleb M.Ageel

Faculty of Computer and IT

Department of IT

Al- Razi University 

Sana’a, Yemen

Yosef A. Abdulmoghni, Eng، Al-Razi University

Faculty of Computer and IT

Department of IT

Al- Razi University
Sana’a, Yemen

Yahya Al-Ashmoery, Prof، Al-Razi University

Faculty of Computer and IT

Department of IT - Al- Razi University

Department of Mathematics & Computer Faculty of Science, Sana’a University

Sana’a, Yemen

منشور
2024-07-20
القسم
المقالات