A filter check system for defeating attacks which employ IP source address spoofing

被引:0
|
作者
Shiraishi, Yoshiaki [1 ]
Fukuta, Youji [1 ]
Morii, Masakatu [1 ]
机构
[1] Nagoya Inst Technol, Nagoya, Aichi 4668555, Japan
关键词
IP spoofing packet; egress filtering; backbone network; ICMP; traceroute;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
To secure network layer is needed for stable IP network as infrastructure. As TCP SYN flooding attack shows, sender of attack packet generally masquerades as others by spoofing source IP address in the packet. IP network becomes more secure, if backbone network through which IP spoofing packet does not flow can be realized. Egress filtering is a way of not flowing IP spoofing packet into backbone network. Each customer network should activate egress filtering for being an effective stratagem. From not only the view point of IP network security but also suppression of threat to be springboard, egress filter must be applied in all customer networks. However, no tool is ready for easily checking egress filtering. In this paper, we show an egress filter check system which can obtain results of egress filter check on routers in a path to arbitrary host.
引用
收藏
页码:289 / +
页数:2
相关论文
共 15 条
  • [11] Preventing DRDoS Attacks in 5G Networks: a New Source IP Address Validation Approach
    Chen, Xu
    Feng, Wei
    Ma, Yinglun
    Ge, Ning
    Wang, xianbin
    2020 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2020,
  • [12] Defending DDoS Attacks in Software-Defined Networking Based on Legitimate Source and Destination IP Address Database
    Wang, Xiulei
    Chen, Ming
    Xing, Changyou
    Zhang, Tingting
    IEICE TRANSACTIONS ON INFORMATION AND SYSTEMS, 2016, E99D (04): : 850 - 859
  • [13] Flexible Deterministic Packet Marking: An IP Traceback System to Find the Real Source of Attacks
    Xiang, Yang
    Zhou, Wanlei
    Guo, Minyi
    IEEE TRANSACTIONS ON PARALLEL AND DISTRIBUTED SYSTEMS, 2009, 20 (04) : 567 - 580
  • [14] IM-Shield: A Novel Defense System against DDoS Attacks under IP Spoofing in High-speed Networks
    Wu, Hua
    Zhang, Xuange
    Chen, Tingzheng
    Cheng, Guang
    Hu, Xiaoyan
    IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC 2022), 2022, : 4168 - 4173
  • [15] Defending Network System against IP Spoofing based Distributed DoS attacks using DPHCF-RTT Packet Filtering Technique
    Maheshwari, Ritu
    Krishna, C. Rama
    Brahma, M. Sridhar
    PROCEEDINGS OF THE 2014 INTERNATIONAL CONFERENCE ON ISSUES AND CHALLENGES IN INTELLIGENT COMPUTING TECHNIQUES (ICICT), 2014, : 206 - 209