首页> 外文会议>Autonomic and Trusted Computing >Real-Time IP Checking and Packet Marking for Preventing ND-DoS Attack Employing Fake Source IPin IPv6 LAN
【24h】

Real-Time IP Checking and Packet Marking for Preventing ND-DoS Attack Employing Fake Source IPin IPv6 LAN

机译:实时IP检查和数据包标记,以防止IPv6 LAN中使用虚假源IP的ND-DoS攻击

获取原文
获取原文并翻译 | 示例

摘要

IPv6 has been proposed as a basic Internet protocol for realizing a ubiquitous computing service. An IPv6 LAN may suffer from a Neighbor Discovery-Denial of Service (ND-DoS) attack, which results in network congestion on the victim IPv6 LAN by making a great number of Neighbor Discovery protocol messages generated. A ND-DoS attacker may use a fake source IP address to hide his/her identity, which makes it more difficult to handle the attack. In this paper, we propose an IP checking and packet marking scheme, which is applied to an IPv6 access router. The proposed scheme can effectively protect IPv6 LAN from ND-DoS attack employing fake source IP by providing the packets suspected to use fake source and/or destination IP addresses with a poor QoS.
机译:已经提出将IPv6作为实现普遍存在的计算服务的基本Internet协议。 IPv6 LAN可能遭受邻居发现拒绝服务(ND-DoS)攻击,这会通过生成大量邻居发现协议消息来导致受害IPv6 LAN上的网络拥塞。 ND-DoS攻击者可能使用伪造的源IP地址来隐藏他/她的身份,这使得处理攻击更加困难。在本文中,我们提出了一种IP检查和数据包标记方案,该方案被应用于IPv6接入路由器。所提出的方案可以通过提供怀疑使用伪造的源IP地址和/或目标IP地址的QoS较差的数据包,有效地保护IPv6 LAN免受使用伪造源IP的ND-DoS攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号