Router Advertisement Suppression in IPv6 Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In IPV6 networks, unauthorized devices can inadvertently or intentionally become designated routers, leading to security issues and network disruptions by advertising false prefixes, which can divert packet traffic and compromise network security.
Innovation Solution
A network device is configured to filter and suppress router advertisements from unauthorized devices, using pre-defined filters to prevent unauthorized devices from becoming default gateways and creating excessive virtual interfaces, thereby enhancing network security and maintainability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Extent of automation
If stateless address autoconfiguration is used in IPV6 networks, then network configuration becomes simpler and more automated, but network security is compromised as unauthorized devices can become designated routers
Solution Approach 1:
The patent introduces a network device as an intermediary between unauthorized devices and the IPV6 network. This intermediary filters router advertisement packets, blocking malicious advertisements while permitting legitimate ones. The network device acts as a mediator that maintains the automated address configuration benefit while preventing security compromises by controlling which devices can become designated routers.
2Adaptability or versatility
If any device can access a physical port and become a designated router, then network adaptability increases, but network stability deteriorates due to unauthorized route advertisements
Solution Approach 1:
The patent applies local quality by treating different network ports differently. The network device is configured to permit router advertisement packets from specific authorized ports while filtering advertisements from other ports. This localized differentiation maintains network adaptability for authorized devices while ensuring stability by blocking unauthorized advertisements from specific locations.
3Ease of operation
If router advertisements are permitted from all ports, then legitimate router functionality is maintained, but unauthorized devices can divert packet traffic and compromise security
Solution Approach 1:
The patent implements preliminary anti-action by proactively filtering router advertisement packets before they can affect the network. The network device is pre-configured with rules to identify and block advertisements from unauthorized devices. This preventive measure counteracts potential harmful actions before they occur, maintaining ease of operation for legitimate routers while preventing unauthorized route diversion.
Data Source
AI summary
In an embodiment, an apparatus for detecting a router advertisement, includes: a network device configured to generate a response when a router advertisement is received in a port in the network device. In another embodiment, a method for detecting a router advertisement, includes: generating a response when a router advertisement is received in a port in the network device.


