Compact Neighbor Discovery: a Bandwidth Defense through Bandwidth Optimization

We present a stateless defense against the Neighbor Discovery Denial-of-Service (ND-DoS) attack in IPv6. The ND-DoS attack may consume important bandwidth in subnets with wireless bridges, or access points. We propose a novel neighbor solicitation technique, that we call Compact Neighbor Discovery (CND), which is based on bandwidth optimization. A bandwidth gain around 40 can be achieved in all cells of the target subnet.
Philippe Nain
Last modified: Tue Mar 15 15:05:21 MET 2005