Identifying Networks Vulnerable to IP Spoofing

Identifying Networks Vulnerable to IP Spoofing
复制标题

DOI:
10.1109/tnsm.2021.3061486
复制
发表时间:
2021-09
影响因子:
5.3
通讯作者:
O. Fonseca;Ítalo F. S. Cunha;E. Fazzion;Wagner Meira Jr;B. A. D. Silva;R. Ferreira;Ethan Katz-Bassett
O. Fonseca;Ítalo F. S. Cunha;E. Fazzion;Wagner Meira Jr;B. A. D. Silva;R. Ferreira;Ethan Katz-Bassett
中科院分区:
计算机科学2区
文献类型:
--
作者:
O. Fonseca;Ítalo F. S. Cunha;E. Fazzion;Wagner Meira Jr;B. A. D. Silva;R. Ferreira;Ethan Katz-Bassett

文献摘要

被引文献

相似文献

由于Internet数据平面缺乏认证,主机可以在数据包头中伪造(欺骗)源IP地址。IP源欺骗是放大拒绝服务(DoS)攻击的基础。目前定位欺骗流量来源的方法缺乏覆盖,或者目前无法部署。我们提出了一种机制,一个具有多个对等链路的网络可以使用它来粗略地定位互联网中欺骗流量的来源。我们的方法背后的想法是,网络可以监控并映射到达对等链路上的欺骗流量到路由到该链路的源集。我们提出了网络可以使用的机制来系统地改变BGP公告配置,以诱导Internet路由和路由到每个对等链路的源集的变化。使用我们的技术的网络可以将多个配置的观测结果关联起来,以更精确地描绘发送欺骗流量的区域。我们的技术在互联网上的评估表明,它们可以将互联网划分为小区域,允许有针对性的干预。
The lack of authentication in the Internet’s data plane allows hosts to falsify (spoof) the source IP address in packet headers. IP source spoofing is the basis for amplification denial-of-service (DoS) attacks. Current approaches to locate sources of spoofed traffic lack coverage or are not deployable today. We propose a mechanism that a network with multiple peering links can use to coarsely locate the sources of spoofed traffic in the Internet. The idea behind our approach is that a network can monitor and map spoofed traffic arriving on a peering link to the set of sources routed toward that link. We propose mechanisms the network can use to systematically vary BGP announcement configurations to induce changes to Internet routes and to the set of sources routed to each peering link. A network using our technique can correlate observations over multiple configurations to more precisely delineate regions sending spoofed traffic. Evaluation of our techniques on the Internet shows that they can partition the Internet into small regions, allowing targeted intervention.