An Authentication Based Source Address Spoofing Prevention Method Deployed in IPv6 Edge Network

An Authentication Based Source Address Spoofing Prevention Method Deployed in IPv6 Edge Network
复制标题

DOI:
10.1007/978-3-540-72590-9_121
复制
发表时间:
2007-05
期刊:
--
影响因子:
--
通讯作者:
Lizhong Xie;J. Bi;Jianping Wu
Lizhong Xie;J. Bi;Jianping Wu
中科院分区:
其他
文献类型:
--
作者:
Lizhong Xie;J. Bi;Jianping Wu

文献摘要

被引文献

相似文献

在当今的Internet路由体系结构中,路由器在转发数据包时不验证数据包中携带的源地址的正确性,也不保留状态信息。因此,假冒IP源地址的DDoS攻击会造成安全问题。在本文中,我们的目标是在细粒度上防止攻击者利用伪造源地址攻击IPv6边缘网络之外的某个地方。提出的方法包括使用会话密钥和哈希摘要算法进行源地址认证,以及结合序列号法和时间戳法防止重放攻击。本文给出了算法设计,并通过仿真实验对其可行性和正确性进行了评价。
In today’s Internet routing architecture, the router doesn’t validate the correctness of the source address carried in the packet, nor keep the state information when forwarding the packet. Thus the DDoS attacks with spoofed IP source address can cause security problems. In this paper, we aim to prevent the attackers from attacking somewhere outside the IPv6 edge network with forged source address in the fine granularity. The proposed methods include source address authentication by using session key and hash digest algorithm, and replay attack prevention by combining the sequence number method and the timestamp method. This paper presents the algorithm design and evaluates its feasibility and correctness by simulation experiments.