Abstract

With technology development, the growing self-communicating devices in IoT networks require specific naming and identification, mainly provided by IPv6 addresses. The IPv6 address in the IoT network is generated by using the stateless auto address configuration (SLAAC) mechanism, and its uniqueness is ensured by the DAD protocol. Recent research suggests that IPv6 deployment can be a risky decision due to the existing SLAAC-based addressing scheme and the DAD protocol being prone to reconnaissance and denial of service (DoS) attacks. This research paper proposes a new IPv6 generation scheme with an improved secure DAD mechanism to address these problems. The proposed addressing scheme generates IPv6 addresses by taking a hybrid approach based on vendor id of medium access control (MAC) address, physical location, and arbitrary random numbers, which mitigates reconnaissance attacks by malicious nodes. To prevent the DAD process from DoS attacks, hybrid values of interface identifier (IID) are multicast instead of actual values. The proposed scheme is evaluated under reconnaissance and DoS attacks in the presence of malicious nodes. The evaluation results demonstrate that the proposed method effectively mitigates reconnaissance and DoS attacks, outperforming the EUI-64 and SEUI-64 schemes in terms of address success rate (ASR), energy consumption, and communication overhead. Specifically, the proposed method significantly reduces the average probing rate for scanning the existence of an IPv6 address, with only a 1% probing rate compared to SEUI-64’s 5% and EUI-64’s 100%. Furthermore, the additional communication overhead introduced by the proposed method is less than 13% and 11% compared to EUI-64 and SEUI-64, respectively. Additionally, the energy consumption required to assign an IPv6 address using the proposed method is lower by 12% and 5% when compared to EUI-64 and SEUI-64, respectively. These findings highlight the effectiveness of the proposed method in enhancing security and optimizing resource utilization in IPv6 addressing.

Details

Title
IPv6 addressing strategy with improved secure duplicate address detection to overcome denial of service and reconnaissance attacks
Author
Kumar, Gyanendra 1 ; Gankotiya, Anil 2 ; Rawat, Sur Singh 3 ; Balusamy, Balamurugan 4 ; Selvarajan, Shitharth 5 

 Manipal University Jaipur, Department of IoT and Intelligent Systems, Jaipur, India (ISNI:0000 0004 4661 2475) 
 Galgotias University, School of Computing Sciences and Engineering, Greater Noida, India (GRID:grid.448824.6) (ISNI:0000 0004 1786 549X) 
 J.S.S. Academy of Technical Education, Department of Computer Science and Engineering, Noida, India (GRID:grid.418403.a) (ISNI:0000 0001 0733 9339) 
 Shiv Nadar University, Delhi-National Capital Region NCR, Delhi, India (GRID:grid.410868.3) (ISNI:0000 0004 1781 342X) 
 Leeds Beckett University, School of Built Environment, Engineering and Computing, Leeds, UK (GRID:grid.10346.30) (ISNI:0000 0001 0745 8880) 
Pages
25148
Publication year
2024
Publication date
2024
Publisher
Nature Publishing Group
e-ISSN
20452322
Source type
Scholarly Journal
Language of publication
English
ProQuest document ID
3120217547
Copyright
© The Author(s) 2024. This work is published under http://creativecommons.org/licenses/by-nc-nd/4.0/ (the “License”). Notwithstanding the ProQuest Terms and Conditions, you may use this content in accordance with the terms of the License.