SAVT: A Practical Scheme for Source Address Validation and Traceback in Campus Network

被引:0
|
作者
Hu, Guangwu [1 ]
Wu, Jianping [1 ]
Xu, Ke [1 ]
Chen, Wenlong [2 ]
机构
[1] Tsinghua Univ, Tsinghua Natl Lab Informat Sci & Technol, Dept Comp Sci & Technol, Beijing 100084, Peoples R China
[2] Univ Sci & Tech Beijing, Sch Informat Engn, Beijing, Peoples R China
关键词
source address validation; traceback; SAVI; SAVT;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
In current network, as we all know, packets delivered by routers only rely on destination-address-directed forwarding, but their source addresses are not checked. Consequently, this incurs many serious network security breach events which are hard to trackback. Under this situation, a switch (we call it SAVI switch) followed SAVI (Source Address Validation Improvement) framework proposed by IETF was invented which dedicates to resolving this problem in user local subnet. SAVI switch is a direct and very effective anti-spoofing device, but because it just steps into a phase of industrialization and for economical and incremental deployment reasons, these switches are not fully covered in domain. This results in two issues at the same time: 1) how to filter out and abandon those packets whose source IP addresses belong to SAVI switches coverage, but actually not, otherwise, this will severely compromise the SAVI switch access users' motivation and SAVI's promotion. 2) how to traceback those packets' source router-the first hop routers of spoofed packets. In this paper, we present SAVT, a practical and smart scheme for source address validation and traceback in campus network for all outbound packets, it just need less 25% routers as filter router can resolve those two questions in most condition. Experiments illustrate our proposal keeps the promise of practicality, stability and efficiency.
引用
收藏
页数:8
相关论文
共 50 条
  • [1] Source Address Validation Improvements In Construction of Campus Network
    Zhu, Zhiyu
    Xu, Xiangyang
    GREEN POWER, MATERIALS AND MANUFACTURING TECHNOLOGY AND APPLICATIONS III, PTS 1 AND 2, 2014, 484-485 : 812 - 816
  • [2] An Effective Traceback Network Attack Procedure for Source Address Verification
    Balraj, Sudhakar
    Leelasankar, Kavisankar
    Ayyanar, Ayyasamy
    Yesudhas, Harold Robinson
    Kumar, Raghvendra
    Long, Hoang Viet
    Hoang Son, Le
    WIRELESS PERSONAL COMMUNICATIONS, 2021, 118 (02) : 1675 - 1696
  • [3] An Effective Traceback Network Attack Procedure for Source Address Verification
    Sudhakar Balraj
    Kavisankar Leelasankar
    Ayyasamy Ayyanar
    Harold Robinson Yesudhas
    Raghvendra Kumar
    Hoang Viet Long
    Le Hoang Son
    Wireless Personal Communications, 2021, 118 : 1675 - 1696
  • [4] The Effectiveness of Passport Source Address Validation Scheme
    Lu, Ning-ning
    Zhou, Hua-chun
    Zhang, Hong-ke
    2009 ASIA-PACIFIC CONFERENCE ON INFORMATION PROCESSING (APCIP 2009), VOL 2, PROCEEDINGS, 2009, : 92 - 95
  • [5] A New Source Address Validation Scheme Based on IBS
    Lu, Ning-ning
    Zhou, Hua-chun
    Zhang, Hong-ke
    FIFTH INTERNATIONAL CONFERENCE ON INFORMATION ASSURANCE AND SECURITY, VOL 2, PROCEEDINGS, 2009, : 334 - 337
  • [6] Practical network support for IP traceback
    Savage, S
    Wetherall, D
    Karlin, A
    Anderson, T
    ACM SIGCOMM COMPUTER COMMUNICATION REVIEW, 2000, 30 (04) : 295 - 306
  • [7] An Incrementally Deployable Network Traceback Scheme
    Tian, Hongcheng
    Wang, Hong
    Li, Li
    2018 IEEE 3RD INTERNATIONAL CONFERENCE ON CLOUD COMPUTING AND BIG DATA ANALYSIS (ICCCBDA), 2018, : 430 - 438
  • [8] Toward Practical Inter-Domain Source Address Validation
    Wang, Xiaoliang
    Xu, Ke
    Guo, Yangfei
    Wang, Haiyang
    Fu, Songtao
    Li, Qi
    Wu, Bin
    Wu, Jianping
    IEEE-ACM TRANSACTIONS ON NETWORKING, 2024, 32 (04) : 3126 - 3141
  • [9] Toward a more practical marking scheme for IP traceback
    Gong, Chao
    Sarac, Kamil
    2006 3RD INTERNATIONAL CONFERENCE ON BROADBAND COMMUNICATIONS, NETWORKS AND SYSTEMS, VOLS 1-3, 2006, : 294 - +
  • [10] A General Framework of Source Address Validation and Traceback for IPv4/IPv6 Transition Scenarios
    Hu, Guangwu
    Xu, Ke
    Wu, Jianping
    Cui, Yong
    Shi, Fan
    IEEE NETWORK, 2013, 27 (06): : 66 - 73