SAVT: A Practical Scheme for Source Address Validation and Traceback in Campus Network

被引:0
|
作者
Hu, Guangwu [1 ]
Wu, Jianping [1 ]
Xu, Ke [1 ]
Chen, Wenlong [2 ]
机构
[1] Tsinghua Univ, Tsinghua Natl Lab Informat Sci & Technol, Dept Comp Sci & Technol, Beijing 100084, Peoples R China
[2] Univ Sci & Tech Beijing, Sch Informat Engn, Beijing, Peoples R China
关键词
source address validation; traceback; SAVI; SAVT;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
In current network, as we all know, packets delivered by routers only rely on destination-address-directed forwarding, but their source addresses are not checked. Consequently, this incurs many serious network security breach events which are hard to trackback. Under this situation, a switch (we call it SAVI switch) followed SAVI (Source Address Validation Improvement) framework proposed by IETF was invented which dedicates to resolving this problem in user local subnet. SAVI switch is a direct and very effective anti-spoofing device, but because it just steps into a phase of industrialization and for economical and incremental deployment reasons, these switches are not fully covered in domain. This results in two issues at the same time: 1) how to filter out and abandon those packets whose source IP addresses belong to SAVI switches coverage, but actually not, otherwise, this will severely compromise the SAVI switch access users' motivation and SAVI's promotion. 2) how to traceback those packets' source router-the first hop routers of spoofed packets. In this paper, we present SAVT, a practical and smart scheme for source address validation and traceback in campus network for all outbound packets, it just need less 25% routers as filter router can resolve those two questions in most condition. Experiments illustrate our proposal keeps the promise of practicality, stability and efficiency.
引用
收藏
页数:8
相关论文
共 50 条
  • [31] Feasible DDoS attack source traceback scheme by deterministic multiple packet marking mechanism
    S. Suresh
    N. Sankar Ram
    The Journal of Supercomputing, 2020, 76 : 4232 - 4246
  • [32] Trace6: A Practical Threatener Traceback Model in IPv6 Network
    Yang, Chaoqiang
    Zhang, Liancheng
    Guo, Yi
    Xia, Wenhao
    Hu, Ming
    Wang, Jichang
    2023 19TH INTERNATIONAL CONFERENCE ON MOBILITY, SENSING AND NETWORKING, MSN 2023, 2023, : 780 - 785
  • [33] A practical scheme for wireless network operation
    Gowaikar, Radhika
    Dana, Amir F.
    Hassibi, Babak
    Effros, Michelle
    IEEE TRANSACTIONS ON COMMUNICATIONS, 2007, 55 (03) : 463 - 476
  • [34] SAVAH: Source Address Validation with Host Identity Protocol
    Kuptsov, Dmitriy
    Gurtov, Andrei
    SECURITY AND PRIVACY IN MOBILE INFORMATION AND COMMUNICATION SYSTEMS, 2009, 17 : 190 - 201
  • [35] Source Address Validation Solution with OpenFlow/NOX Architecture
    Yao, Guang
    Bi, Jun
    Xiao, Peiyao
    2011 19TH IEEE INTERNATIONAL CONFERENCE ON NETWORK PROTOCOLS (ICNP), 2011,
  • [36] Deployment and validation of out of band IP traceback approach (OBTA) in wireless mesh network
    Gassara, Mouna
    Bouabidi, Imen
    Zarai, Faouzi
    Obaidat, Mohammad S.
    Hsiao, Kuei-Fang
    INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2018, 31 (10)
  • [37] Practical Source-Network Decoding
    Maierbacher, Gerhard
    Barros, Joao
    Medard, Muriel
    2009 6TH INTERNATIONAL SYMPOSIUM ON WIRELESS COMMUNICATION SYSTEMS (ISWCS 2009), 2009, : 283 - +
  • [38] An Analysis of Resource Sharing Scheme in Heterogeneous Wireless Campus Network
    Masud, M. H.
    Latif, S. A.
    Anwar, F.
    Abdalla, A. H.
    Alam, M. K.
    2013 INTERNATIONAL CONFERENCE ON COMPUTING, ELECTRICAL AND ELECTRONICS ENGINEERING (ICCEEE), 2013, : 653 - 658
  • [39] Preventing Utilization of Shared Network Resources by Detecting IP Spoofing Attacks through Validation of source IP Address
    Lema, Hussein
    Simba, Fatuma
    Ally, Abdulla
    2018 IST-AFRICA WEEK CONFERENCE (IST-AFRICA), 2018,
  • [40] A MAC address based authentication system applicable to campus-scale network
    Watanabe, Yoshiaki
    Otani, Makoto
    Eto, Hirofumi
    Watanabe, Kenzi
    Tadaki, Shin-ichi
    2013 15TH ASIA-PACIFIC NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM (APNOMS), 2013,