首页> 中文期刊> 《清华大学学报(英文版)》 >Preventing IP Source Address Spoofing: A Two-Level,State Machine-Based Method

Preventing IP Source Address Spoofing: A Two-Level,State Machine-Based Method

         

摘要

A signature-and-verification-based method, automatic peer-to-peer anti-spoofing (APPA), is pro-posed to prevent IP source address spoofing. In this method, signatures are tagged into the packets at the source peer, and verified and removed at the verification peer where packets with incorrect signatures are filtered. A unique state machine, which is used to generate signatures, is associated with each ordered pair of APPA peers. As the state machine automatically transits, the signature changes accordingly. KISS ran-dom number generator is used as the signature generating algorithm, which makes the state machine very small and fast and requires very low management costs. APPA has an intre-AS (autonomous system) level and an inter-AS level. In the intra-AS level, signatures are tagged into each departing packet at the host and verified at the gateway to achieve finer-grained anti-spoofing than ingress filtering. In the inter-AS level, signatures are tagged at the source AS border router and verified at the destination AS border muter to achieve prefix-level anti-spoofing, and the automatic state machine enables the peers to change signatures without negotiation which makes APPA attack-resilient compared with the spoofing prevention method. The results show that the two levels are both incentive for deployment, and they make APPA an integrated anti-spoofing solution.

著录项

  • 来源
    《清华大学学报(英文版)》 |2009年第4期|413-422|共10页
  • 作者单位

    Tsinghua National Laboratory for Information Science and Technology, Network Research Center,Tsinghua University, China Education and Research Network (CERNET), Beijing 100084, China;

    Tsinghua National Laboratory for Information Science and Technology, Network Research Center,Tsinghua University, China Education and Research Network (CERNET), Beijing 100084, China;

    Tsinghua National Laboratory for Information Science and Technology, Network Research Center,Tsinghua University, China Education and Research Network (CERNET), Beijing 100084, China;

    Tsinghua National Laboratory for Information Science and Technology, Network Research Center,Tsinghua University, China Education and Research Network (CERNET), Beijing 100084, China;

  • 原文格式 PDF
  • 正文语种 chi
  • 中图分类 计算技术、计算机技术;
  • 关键词

获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号