Network Ingress Filtering: Defeating Denial of Service Attacks which employ IP Source Address Spoofing

Network Ingress Filtering: Defeating Denial of Service Attacks which employ IP Source Address Spoofing
复制标题

DOI:
10.17487/rfc2267
复制
发表时间:
1998
期刊:
RFC
影响因子:
--
通讯作者:
Paul Ferguson;D. Senie
Paul Ferguson;D. Senie
中科院分区:
其他
文献类型:
--
作者:
Paul Ferguson;D. Senie

文献摘要

被引文献

相似文献

最近发生的各种使用伪造源地址的拒绝服务攻击已被证明是互联网服务提供商和整个互联网社区的一个棘手问题。本文讨论了一种简单、有效和直接的方法,使用入口流量过滤来禁止使用伪造IP地址从互联网服务提供商(ISP)聚集点后面传播的DoS攻击。
Recent occurrences of various Denial of Service (DoS) attacks which have employed forged source addresses have proven to be a troublesome issue for Internet Service Providers and the Internet community overall. This paper discusses a simple, effective, and straightforward method for using ingress traffic filtering to prohibit DoS attacks which use forged IP addresses to be propagated from 'behind' an Internet Service Provider's (ISP) aggregation point.