Revisiting inter-AS IP Spoofing Let the Protection Drive Source Address Validation

被引:0
|
作者
Jia, Yihao [1 ,2 ,3 ]
Liu, Ying [1 ,3 ]
Ren, Gang [1 ,3 ]
He, Lin [1 ,2 ,3 ]
机构
[1] Tsinghua Univ, Inst Network Sci & Cyberspace, Beijing 100084, Peoples R China
[2] Tsinghua Univ, Dept Comp Sci & Technol, Beijing 100084, Peoples R China
[3] Tsinghua Natl Lab Informat Sci & Technol, Beijing 100084, Peoples R China
基金
中国国家自然科学基金;
关键词
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
IP spoofing, which is prevalently used for anonymity and reflection attacks, has shown increasing destructive power in recent years. Although certain source address validation solutions have been standardized by the Internet Engineering Task Force, few networks are willing to adopt them in view of the deficiency of deployment benefits. Actually, all the source address validation solutions face the problem of a lack of deployability. In this paper, we summarize the key points describing deployability and propose a new security service-inter-autonomous-system (AS) Source Address Protection (iSAP). Technically, by increasing the possibility of keeping the source address belonging to one AS from being the victim of reflection flooding, iSAP improves the deployers ability to prevent IP spoofing and increases incremental deployability. In reality, such a service can also be regarded as a new profit opportunity for ASes and it could progress gradually once it is well commercialized. Based on simulations with real Internet topology data, the results illustrate that iSAP can protect ASes from being reflected with only a few deployers, exhibiting a high potential to mitigate reflection flooding with modest resource consumption.
引用
收藏
页数:10
相关论文
共 18 条
  • [1] Address Protection-as-a-Service An inter-AS Framework for IP Spoofing Resilience
    Jia, Yihao
    Liu, Ying
    Ren, Gang
    2019 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2019,
  • [2] pSAV: A Practical and Decentralized Inter-AS Source Address Validation Service Framework
    Cao, Jiamin
    Liu, Ying
    Liu, Mingxing
    He, Lin
    Jia, Yihao
    Yang, Fei
    2021 IEEE/ACM 29TH INTERNATIONAL SYMPOSIUM ON QUALITY OF SERVICE (IWQOS), 2021,
  • [3] Preventing Utilization of Shared Network Resources by Detecting IP Spoofing Attacks through Validation of source IP Address
    Lema, Hussein
    Simba, Fatuma
    Ally, Abdulla
    2018 IST-AFRICA WEEK CONFERENCE (IST-AFRICA), 2018,
  • [4] SAV6: A Novel Inter-AS Source Address Validation Protocol for IPv6 Internet
    He, Lin
    Ren, Gang
    Liu, Ying
    Song, Guanglei
    Jinlong, E.
    Yang, Jiahai
    Xu, Mingwei
    IEEE NETWORK, 2023, 37 (05): : 64 - 70
  • [5] RISP: An RPKI-Based Inter-AS Source Protection Mechanism
    Jia, Yihao
    Liu, Ying
    Ren, Gang
    He, Lin
    TSINGHUA SCIENCE AND TECHNOLOGY, 2018, 23 (01) : 1 - 12
  • [6] IP source address spoofing filtering based on Bloom filter
    Yan, Qiao
    Shenzhen Daxue Xuebao (Ligong Ban)/Journal of Shenzhen University Science and Engineering, 2009, 26 (02): : 132 - 136
  • [7] RISP:An RPKI-Based Inter-AS Source Protection Mechanism
    Yihao Jia
    Ying Liu
    Gang Ren
    Lin He
    TsinghuaScienceandTechnology, 2018, 23 (01) : 1 - 12
  • [8] LSAV: Lightweight source address validation in SDN to counteract IP spoofing-based DDoS attacks
    Karakoc, Ali
    Alagoz, Fatih
    TURKISH JOURNAL OF ELECTRICAL ENGINEERING AND COMPUTER SCIENCES, 2023, 31 (07) : 1187 - 1205
  • [9] A filter check system for defeating attacks which employ IP source address spoofing
    Shiraishi, Yoshiaki
    Fukuta, Youji
    Morii, Masakatu
    WMSCI 2007: 11TH WORLD MULTI-CONFERENCE ON SYSTEMICS, CYBERNETICS AND INFORMATICS, VOL II, PROCEEDINGS, 2007, : 289 - +
  • [10] SAVSH: IP Source Address Validation for SDN Hybrid Networks
    Chen, Guolong
    Hu, Guangwu
    Jiang, Yong
    Zhang, Chaoqin
    2016 IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATION (ISCC), 2016, : 409 - 414