An Authentication Based Source Address Spoofing Prevention Method Deployed in IPv6 Edge Network
An Authentication Based Source Address Spoofing Prevention Method Deployed in IPv6 Edge Network
复制标题
DOI:
10.1007/978-3-540-72590-9_121
复制
发表时间:
2007-05
期刊:
影响因子:
--
通讯作者:
Lizhong Xie;J. Bi;Jianping Wu
中科院分区:
文献类型:
--
作者:
Lizhong Xie;J. Bi;Jianping Wu
In today’s Internet routing architecture, the router doesn’t validate the correctness of the source address carried in the packet, nor keep the state information when forwarding the packet. Thus the DDoS attacks with spoofed IP source address can cause security problems. In this paper, we aim to prevent the attackers from attacking somewhere outside the IPv6 edge network with forged source address in the fine granularity. The proposed methods include source address authentication by using session key and hash digest algorithm, and replay attack prevention by combining the sequence number method and the timestamp method. This paper presents the algorithm design and evaluates its feasibility and correctness by simulation experiments.