DHCPAuth - A DHCP message authentication module
نویسندگان
چکیده
DHCP is one of the most used network protocols, despite the security issues it has. Our work is motivated by the numerous attacks that can be launched against DHCP and the impact that they can have. Firstly, we formulate the constraints and design principles for a DHCP message authentication module that is flexible and easy to integrate with current DHCP implementations, while providing the necessary level of security. Then we present DHCPAuth, a module for authenticating DHCP messages. The module uses the RFC 3118 authentication option format and is able to authenticate DHCP client and server messages using two trust models: PKI and PGP. The proposed module is evaluated using different public key pairs in the considered trust models to determine the overhead introduced and the impact on DHCP operation. Results show the additional time required to process the DHCP messages, either when signing or verifying the signatures, as well as the authentication option length and the DHCP packet length. We also provide an analysis of worse case time for verifying the authentication option when more certificates or public keys are available on certificate store or public key ring. These information can help network administrators in selecting the trust model, the key types and sizes to use.
منابع مشابه
DHCP Message Authentication with an Effective Key Management
In this paper we describes the authentication for DHCP (Dynamic Host Configuration Protocol) message which provides the efficient key management and reduces the danger replay attack without an additional packet for a replay attack. And the authentication for DHCP message supports mutual authentication and provides both entity authentication and message authentication. We applied the authenticat...
متن کاملA Secure DHCP Protocol to Mitigate LAN Attacks
Network security has become more of a concern with the rapid growth and expansion of the Internet. While there are several ways to provide security in the application, transport, or network layers of a network, the data link layer (Layer 2) security has not yet been adequately addressed. Data link layer protocols used in local area networks (LANs) are not designed with security features. Dynami...
متن کاملProcedures and IANA Guidelines for Definition of New DHCP Options and Message Types
The Dynamic Host Configuration Protocol (DHCP) provides a framework for passing configuration information to hosts on a Transmission Control Protocol/Internet Protocol (TCP/IP) network. Configuration parameters and other control information are carried in tagged data items that are stored in the 'options' field of the DHCP message. The data items themselves are also called "options". DHCP proto...
متن کاملDRAFT Defining New DHCP Options
Status of this memo This document is an Internet-Draft and is in full conformance with all provisions of Section 10 of RFC2026. Internet-Drafts are working documents of the Internet Engineering Task Force (IETF), its areas, and its working groups. Note that other groups may also distribute working documents as Internet-Drafts. Internet-Drafts are draft documents valid for a maximum of six month...
متن کاملDRAFT Defining New DHCP Options
Status of this memo This document is an Internet-Draft and is in full conformance with all provisions of Section 10 of RFC2026. Internet-Drafts are working documents of the Internet Engineering Task Force (IETF), its areas, and its working groups. Note that other groups may also distribute working documents as Internet-Drafts. Internet-Drafts are draft documents valid for a maximum of six month...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2015