First Hop Switch IPv6 NDP Interception for Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
IPv6 network traffic is vulnerable to security threats due to shared layer-2 physical networks, where rogue users can intercept and exploit Neighbor Discovery Protocol (NDP) exchanges, leading to attacks like man-in-the-middle and denial-of-service attacks.
Innovation Solution
A first hop switch intercepts NDP messages, compares address information with a local device tracking cache, and performs end node discovery and tracking, creating bindings between Link Layer Addresses (LLA) and IPv6 addresses to verify identities and prevent unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a shared layer-2 physical network infrastructure is used to transport IPv6 traffic, then network resource utilization and user mobility are improved, but network security deteriorates due to vulnerability to rogue users and attacks
Solution Approach 1:
The patent introduces an intermediary security mechanism at the first-hop switch that mediates NDP message exchanges between end hosts and routers. This intermediary validates address bindings, monitors neighbor discovery processes, and filters malicious traffic, thereby protecting the shared layer-2 network from rogue users while maintaining its resource utilization benefits
Solution Approach 2:
The patent implements preliminary security actions by pre-establishing address bindings between link layer addresses and IPv6 addresses before actual data transmission occurs. The first-hop switch performs advance validation of neighbor discovery messages and proactively identifies rogue devices, preventing attacks before they can compromise network security
2Ease of operation
If NDP exchanges are allowed to proceed without interception, then network protocol functionality and ease of operation are maintained, but security against spoofing and man-in-the-middle attacks deteriorates
Solution Approach 1:
The first-hop switch acts as an intermediary that transparently intercepts and validates NDP messages without disrupting the normal neighbor discovery process. It maintains protocol functionality by allowing legitimate NDP exchanges while filtering out spoofed messages, thus preserving ease of operation while enhancing security
Solution Approach 2:
The patent implements feedback mechanisms where the first-hop switch monitors NDP message exchanges, validates address bindings, and provides real-time security enforcement. The switch uses feedback from intercepted messages to dynamically update its security state and block malicious traffic, maintaining protocol functionality while preventing attacks
Data Source
AI summary
Network security and tracking techniques are provided for intercepting at a first hop switch a neighbor discovery protocol (NDP) message sent from an end node of an Internet Protocol Version 6 (IPV6) network. Address information contained in the NDP message are compared to values stored in a local device tracking cache. As a result of the comparing, end node discovery and learning are performed.


