I-D Action: draft-gashinsky-6man-v6nd-enhance-00.txt

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



A New Internet-Draft is available from the on-line Internet-Drafts directories.

	Title           : Neighbor Discovery Enhancements for DOS mititgation
	Author(s)       : Warren Kumari
	Filename        : draft-gashinsky-6man-v6nd-enhance-00.txt
	Pages           : 13
	Date            : 2012-01-08

   In IPv4, subnets are generally small, made just large enough to cover
   the actual number of machines on the subnet.  In contrast, the
   default IPv6 subnet size is a /64, a number so large it covers
   trillions of addresses, the overwhelming number of which will be
   unassigned.  Consequently, simplistic implementations of Neighbor
   Discovery can be vulnerable to denial of service attacks whereby they
   attempt to perform address resolution for large numbers of unassigned
   addresses.  Such denial of attacks can be launched intentionally (by
   an attacker), or result from legitimate operational tools that scan
   networks for inventory and other purposes.  As a result of these
   vulnerabilities, new devices may not be able to "join" a network, it
   may be impossible to establish new IPv6 flows, and existing ipv6
   transported flows may be interrupted.

   This document describes possible modifications to the traditional
   [RFC4861] neighbor discovery protocol for improving the resilience of
   the neighbor discovery process as well as an alternative method for
   maintaining ND caches.


A URL for this Internet-Draft is:
http://www.ietf.org/internet-drafts/draft-gashinsky-6man-v6nd-enhance-00.txt

Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/

This Internet-Draft can be retrieved at:
ftp://ftp.ietf.org/internet-drafts/draft-gashinsky-6man-v6nd-enhance-00.txt

_______________________________________________
I-D-Announce mailing list
I-D-Announce@ietf.org
https://www.ietf.org/mailman/listinfo/i-d-announce
Internet-Draft directories: http://www.ietf.org/shadow.html
or ftp://ftp.ietf.org/ietf/1shadow-sites.txt


[Index of Archives]     [IETF]     [IETF Discussion]     [Linux Kernel]

  Powered by Linux