Show simple item record

Voucher-Based Addressing & Sessions: A Simple, Flexible, Privacy-Preserving Recipe for Mitigating IPv6 Neighbor Discovery Redirection Attacks

dc.contributor.authorPuhl, Zachary Tyler
dc.contributor.advisorGuo, Jinhua
dc.date.accessioned2024-07-12T19:09:32Z
dc.date.issued2024-12-20
dc.date.submitted2024-06-20
dc.identifier.urihttps://hdl.handle.net/2027.42/194096
dc.description.abstractThe vast majority of local IPv6 networks continue to remain insecure and vulnerable to neighbor spoofing attacks, a fearsomely practical attack vector formally described many years ago. The Secure Neighbor Discovery (SEND) standard and its concomitant Cryptographically Generated Addressing (CGA) scheme were introduced, revised, and adopted by large standards bodies to codify practical mitigations. Considering their poor adoption, much research since their acceptance has continued to find new perspectives and proffer new ideas. The orthodox solutions for securing Neighbor Discovery traffic have historically struggled to successfully harmonize three core ideals: simplicity, flexibility, and privacy preservation. This research introduces an alternative to IPv6 address generation methods that secures the Neighbor Discovery address resolution process while remaining highly adaptable, indistinguishable, and privacy-focused. Applying a unique concoction of cryptographic key derivation functions, hash chaining, link-layer address binding, and neighbor consensus on the parameters of address generation, local address ownership is verifiable without the need for techniques that have hindered the adoption of the canonical specifications. Voucher-Based Addressing and end-to-end Neighbor Discovery Sessions are presented as synergistic, low-configuration, low-cost, and high-impact specifications for securing local networks against neighbor spoofing attacks.en_US
dc.language.isoen_USen_US
dc.subjectIPv6en_US
dc.subjectSecurityen_US
dc.subjectNetworkingen_US
dc.subjectNDPen_US
dc.subjectNeighbor Discoveryen_US
dc.subjectSpoofingen_US
dc.subjectPrivacyen_US
dc.subject.otherComputer and Information Scienceen_US
dc.titleVoucher-Based Addressing & Sessions: A Simple, Flexible, Privacy-Preserving Recipe for Mitigating IPv6 Neighbor Discovery Redirection Attacksen_US
dc.typeThesisen_US
dc.description.thesisdegreenameMaster of Science (MS)en_US
dc.description.thesisdegreedisciplineComputer and Information Science, College of Engineering & Computer Scienceen_US
dc.description.thesisdegreegrantorUniversity of Michigan-Dearbornen_US
dc.contributor.committeememberMa, Di
dc.contributor.committeememberEshet, Birhanu
dc.identifier.uniqnamezpuhlen_US
dc.description.bitstreamurlhttp://deepblue.lib.umich.edu/bitstream/2027.42/194096/1/Puhl_Thesis_Voucher_Based_Addressing.pdf
dc.identifier.doihttps://dx.doi.org/10.7302/23540
dc.description.mappingfebc42ae-d444-43ae-98fd-dc98ee638897en_US
dc.identifier.orcid0009-0001-6955-8104en_US
dc.description.filedescriptionDescription of Puhl_Thesis_Voucher_Based_Addressing.pdf : Dissertation
dc.working.doi10.7302/23540en_US
dc.owningcollnameDissertations and Theses (Ph.D. and Master's)


Files in this item

Show simple item record

Remediation of Harmful Language

The University of Michigan Library aims to describe library materials in a way that respects the people and communities who create, use, and are represented in our collections. Report harmful or offensive language in catalog records, finding aids, or elsewhere in our collections anonymously through our metadata feedback form. More information at Remediation of Harmful Language.

Accessibility

If you are unable to use this file in its current format, please select the Contact Us link and we can modify it to make it more accessible to you.