년 - 년
보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.10 No.4 2016.04 pp.143-154
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
Most IPv6 security issues are still the same as IPv4; IPv6 has its own unique design characteristics that have additional impact to system and network security, as well as the potential impact on policies and procedures. Address autoconfiguration is a key feature of the IPv6 protocol stack that allow hosts to generate own addresses using a confluence of information from other hosts and information from router advertisement. Duplicate Address Detection (DAD) is a process that is part of address autoconfiguration that is used to check if the addresses generated has already been configured. Nevertheless, the design of DAD process is vulnerable to Denial of Service (DoS) attack leaving hosts unconfigured. For example, any host can reply to Neighbor Solicitations (NS) for a temporary address, causing the other host to consider it as a duplicate and eventually reject the address. Various mechanisms such as SeND and SAVI has been introduced to address such attacks, but these techniques were not very effective as there were still possibilities of DoS attacks to be carried out. As such, a new mechanism is needed to more effectively prevent DoS attacks on DAD process. In this paper, we present a detailed design and development of a novel mechanism that can address the shortfalls of existing prevention techniques.
보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.9 No.11 2015.11 pp.77-86
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
In addition to addressing the scarcity of IP address space, Internet Protocol version 6 (IPv6) also addressed some of the shortcomings of Internet Protocol version 4(IPv4). These include neighbor discovery, address auto-configuration, and others. Many of this message exchange are done via the Internet Control Message Protocol (ICMP) and the use of this protocol in the IPv6 paradigm, i.e. ICMPv6 plays a bigger role compared to ICMPv4. One of the key process that is carried during neighbor discovery process is to check if the address generated already exists. This process is called the Duplicate Address Detection (DAD). Nevertheless, the design of this process has led to a severe security vulnerability allowing attackers to easily carry out Denial-of-Service (DoS) attack by causing every address generated to be a duplicate leading to new hosts unable to join the network. Various techniques and mechanisms have been introduced to address this vulnerability such as NDPMon, SeND, and SAVA. Nevertheless, these techniques are either not robust or have performance implications vis-à-vis with the DAD DoS detection and mitigation. In this paper, we put forward a novel framework that is able to detect, mitigate DoS attacks while being light-weight at the same time.
Mobile Ad-Hoc Network에서 주소 자동화 메커니즘 설계 및 평가 KCI 등재후보
국제인공지능학회(구 한국인터넷방송통신학회) 한국인터넷방송통신학회 논문지 제7권 제3호 2007.06 pp.9-14
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
최근 MANET에서 라우팅 프로토콜이 표준화되면서 라우팅을 위한 IP 주소 할당에 관심이 모아져 이에 대한 연구가 이루어지고 있다. 그러나 지금까지 MANET의 주소 할당 메커니즘들은 대부분 DAD 기법 연구에 초점이 맞추어져 주소 할당에 따른 지연과 효율적이지 못한 주소 공간 활용이라는 문제점을 가지고 있으며 이러한 문제점을 해결하기 위하여 본 논문에서는 주소를 sequence하게 회수시킴으로써 주소 활용도를 높이고 주소 할당에 있어 DCDP를 사용함으로써 주소 중복 문제를 해결한 SARM(Sequence Address Range Mechanism)을 제안한다. 마지막으로 수학적 분석을 통하여 주소 설정 시간과 IP 주소 활용도 측면에서 기존 방식보다 우수함을 증명하였다.
As MANET routing protocol was recently standardized, IP address allocation has attracted significant interest in many studies. However, most of MANET address allocation mechanisms focus on the study of DAD technique. So, some key challenges still remain such as latency in address allocation and inefficient space utilization. In order to solve these problems, we suggests in this paper Sequence Address Range Mechanism (SARM), which enhances the degree of address utilization by sequentially recovering addresses and solves the problem of address duplication by applying DCDP for address allocation. Also, we prove that SARM is better than the existing address autoconfiguration mechanism in terms of address allocation time and IP address utilization, through numerical analysis.
동일한 네트워크 프리픽스를 갖는 다중 게이트웨이 기반의 connected MANET에서 주소 자동 설정 방법
[Kisti 연계] 한국정보과학회 정보과학회논문지:정보통신 Vol.36 No.5 2009 pp.405-412
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
이동 애드 혹 망(MANET)은 유선 인프라스트럭처의 도움 없이 이동 노드들 간에 서로 협력하여 무선 다중-홉으로 통신을 할 수 있도록 해주는 네트워크이다. MANET에서는 서로의 전파 범위에 있지 않은 노드들 간에 통신할 수 있도록 해주는 경로 설정 방법뿐만 아니라 노드들이 스스로 주소를 설정할 수 있도록 해주는 주소 설정 기법이 필수적이다. MANET에서 주소 설정을 위한 여러가지 기법들이 제안되었다. 특히 MANET이 게이트웨이를 이용하여 인터넷과 같은 외부 네트워크와 연결되는 형태의 connected MANET에서는 노드들이 인터넷 토폴로지에 적합한 전역 주소를 가지고 있어야 한다. 이 논문에서는 여러 개의 게이트웨이를 이용하여 MANET과 외부 네트워크가 연결되어 있는 환경에서 모든 게이트웨이가 동일한 네트워크 프리픽스를 MANET에 광고하는 경우에, 일단 노드가 하나의 주소를 설정하면 노드가 이동을 하더라도 이미 설정된 주소를 계속 이용할 수 있도록 하기 위한 메커니즘을 제안한다. 제안된 방법의 성능은 모의실험을 통하여 분석되었으며, 분석된 결과는 제안 기법이 기존에 방법에 비하여 향상된 성능을 제공한다는 것을 보여준다.
Mobile ad hoc networks (MANETs) allow mobile nodes to communicate among themselves via wireless multiple hops without the help of the wired infrastructure. In the MANET, it is required not only a route setup mechanism that makes nodes not within each other's transmission range communicate but also mechanism in order for a node to auto-configure a unique address. In this paper, we propose an address auto-configuration mechanism when MANET is connected to the Internet via several Internet Gateways and all gateways advertise the same network prefix. By using the proposed mechanism, once a node configures an Internet topologically correct and globally unique IP address, then the node can utilize the configured address even though the node moves within the MANET. Through the simulations, we analyze the performance of our proposed mechanism and, from the simulation results, we show that out proposed mechanism outperforms the existing mechanism.
Mobile IPv6기반 Ad-Hoc 네트워크에서의 Internet Gateway를 통한 IP주소 자동 할당 방법
[Kisti 연계] 대한전자공학회 대한전자공학회 학술대회논문집 2005 pp.1067-1070
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
In this paper, we propose the address allocation algorithm in hybrid Mobile ad-hoc network (MANET). Most of proposed address autoconfiguration algorithms are node based. Node based address autoconfiguration algorithms are inefficient. Because the node based algorithms waste bandwidth and consume much battery in mobile ad-hoc networks. we present the address allocation algorithm using internet gateway based address autoconfiguration by modifing the IPv6 stateless address autoconfiguration protocol. We use the network simulator NS-2 in our experiments. The simulation result shows reducing network traffic and saving battery.
Mobile Ad Hoc Network 에서의 계층적 자동주소 할당 방법
[Kisti 연계] 한국통신학회 한국통신학회 학술대회논문집 2006 p.530
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
모바일 Ad-Hoc 네트워크에서 MIPv6 주소자동할당 프로토콜
[Kisti 연계] 한국지능시스템학회 한국지능시스템학회 학술대회논문집 2006 pp.103-106
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
모바일 애드 혹 네트워크(Mobile Ad-hoc Network)는 기반 통신시설의 도움 없이 노드들 간에 자율적으로 구성되는 무선 네트워크로 각 노드는 이동성 및 다른 노드에게 패킷을 전달하는 라우팅 기능을 가지고 있다. 현재까지 모바일 애드혹 네트워크의 주된 관심사는 경로설정 문제를 해결하는데 있었다. 모바일 애드혹 네트워크의 라우팅 프로토콜에서 노드에게 할당된 주소가 유일한 것으로 가정하여 사용하지만 경로설정에 앞서 모바일 애드 혹 네트워크에 참여하는 노드에게 어떤 방법으로 유일한 주소를 제공할 것 인가에 대한 연구가 필요하다. 특히 모바일 애드 혹 네트워크는 필요에 따라 노드들이 자발적으로 네트워크를 형성하여 데이터를 주고 받는 형태이기 때문에 노드들에게 동적으로 주소를 할당하는 문제는 매우 중요하다. 따라서 모바일 애드혹 네트워크가 외부망과 연결시 고정 IP을 부여하고 애드혹의 구성하는 노드이 이동성을 고려하여 노드들 간의 분산된 IP 주소 자동 할당 방법을 MIPv6 적용한 프로토콜을 제안한다. 또한 평가방법으로 이동성을 고려하여 네트워크의 크기를 노드의 수를 가지고 비교하여 모바일 애드혹 네트워크를 구성하는 노드의 수를 증가함으로 기존 연구와 비교평가를 위해서 시뮬레이션 환경을 구현하여 실험을 수행하였다. 실험 결과, 이 논문에서 제안한 방법을 사용하면 모바일 애드혹 네트워크의 크기가 커질수록 기존의 방법보다 주소할당 소요시간을 감소시킬 수 있다.
Large-scale MANET에서의 동적 주소 할당에 관한 연구
[Kisti 연계] 한국정보과학회 한국정보과학회 학술대회논문집 2004 pp.598-600
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
Mobile Ad hoc Network (MANET)는 자율적으로 작동할 수 있는 멀티 홈 무선 네트워크로서 토폴로지 변화가 자주 일어나며 예측할 수 없는 특성을 갖는다. 특히 scale 이 큰 MANET 환경에서는 더욱더 예측할 수 없는 특성을 갖게 된다. 최근 MANET에서의 라우팅을 하기 위한 주소 할당에 관심이 모아지고 있는 상황에서 각 노드는 DHCP 같은 서버의 역할 없이 주소를 할당할 수 있는 기능을 가져야 하며, 이동 단말들이 모두 IP stack을 지원하는 것을 감안해서 IP주소를 사용해야할 것이다. 따라서 본 논문에서는 scale이 큰 MANET 환경에서 동적으로 IP 주소를 할당하는 방법을 제안한다.
개선된 CGA(Modified CGA)를 이용한 계층적 애드 혹 네트워크에서의 주소 자동 설정 및 전자 서명 제공 방안
[Kisti 연계] 한국정보과학회 정보과학회논문지:정보통신 Vol.33 No.2 2006 pp.175-182
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
IPv6 워킹 그룹에서 표준화된 CGA(Cryptographically Generated Addresses)는 링크상에서의 주소 변조 및 주소 도난 문제를 해결하고 전자서명을 제공하기 위해 제안되었으나 키 충돌이라는 문제가 발생할 수 있어서 이를 해결하기 위해 SEC(SECurity parameter) 필드를 도입하여 높은 보안이 필요한 경우에는 높은 SEC 값을 적용함으로써 키 충돌 확률을 감소시킨다. 하지만 SEC 값이 증가함에 따라 CGA 생성 시간이 무제한으로 증가하기 때문에 무선 환경에서 SEC 값이 높은 CGA를 적용하는 것은 불가능하다. 또, 낮은 SEC 값을 적용하는 경우 키 충돌은 높은 확률로 발생한다. 따라서, 본 논문에서는 계층적 애드 혹 환경에 적합한 개선된 CGA(MCGA: Modified CGA)를 제안한다. 제안되는 MCGA는 CGA에 비해 생성 시간이 매우 짧고 CGA와 마찬가지로 매우 작은 오버헤드로 전자 서명을 제공하며 계층적 네트워크 환경에서 사용함으로써 키 충돌 문제를 해결한다. MCGA는 계층적 애드 혹 환경뿐만 아니라 일반 IPv6 네트워크에서도 적용이 가능하다. 본 논문에서는 먼저 수학적 모델을 통해 MCGA와 CGA의 생성 시간을 분석하고 시뮬레이션을 통해 CGA와 MCGA의 생성시간을 측정하여 MCGA가 SEC 값이 0인 경우의 CGA에 비해 생성 시간이 평균 3.3배, 그리고 SEC 값이 1인 경우에는 평균 68,000배 짧다는 것을 보인다. 특히 SEC 값이 3 이상인 경우 애드 혹 환경뿐만 아니라 일반 네트워크에서도 부적절하다는 것을 증명한다.
The CGA proposed by IETF working group prevents address spoofing and stealing and provides digital signature to users, but key collision problem arises. To solve this critical problem, the CGA defines the SEC field within address format, which is set to high value when high security is required and vice versa, but the CGA faces a dilemma between security and the processing time. As SEC value increases, the processing time to generate the CGA grows dramatically while key collision ratio increases if low SEC value is applied to the CGA. We propose modified CGA (MCGA) that has shorter processing time than the CGA and offers digital signature with small overheads. To solve key collision problem, we employ hierarchical ad hoc network. The MCGA is applicable to IPv6 networks as well public networks. In this paper, we design a mathematical model to analyze the processing time for MCGA and CGA first and evaluate the processing time via simulations, where the processing time for MCGA is reduced down 3.3 times when SEC value is set to 0 and 68,000 times when SEC value is set to 1. Further, we have proved that the CGA is inappropriate for both ad hoc networks and IPv6 networks when the SEC field is set to more than 3.
IPv6 모바일 Ad-hoc 네트워크에서의 자동주소지정을 위한 중복주소탐지
[Kisti 연계] 한국정보과학회 한국정보과학회 학술대회논문집 2004 pp.565-567
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
All IP,NGN(Next Generation Network)으로 대변되는 차세대 네트워크의 특징 중 하나는 이동성이며 노드의 이동뿐만 아니라 네트워크 전체가 이동하는 모바일 네트워크로 진화하고 있다. 차세대 네트워크의 하위 구조를 이루게 될 MANET에 IPv6를 적용하기 위해, 보다 확장성 있고, 유연하며. 빠르고 가벼운 IPv6의 자동 주소 지정 및 중복 주소 탐지에 관해 논의한다.
0개의 논문이 장바구니에 담겼습니다.
선택하신 파일을 압축중입니다.
잠시만 기다려 주십시오.