Preventing IP Source Address Spoofing: A Two-Level, State Machine-Based Method

来源 :Tsinghua Science and Technology | 被引量 : 0次 | 上传用户:chaoge100
下载到本地 , 更方便阅读
声明 : 本文档内容版权归属内容提供方 , 如果您对本文有版权争议 , 可与客服联系进行内容授权或下架
论文部分内容阅读
A signature-and-verification-based method, automatic peer-to-peer anti-spoofing (APPA), is proposed to prevent IP source address spoofing. In this method, signatures are tagged into the packets at the source peer, and verified and removed at the verification peer where packets with incorrect signatures are filtered. A unique state machine, which is used to generate signatures, is associated with each ordered pair of APPA peers. As the state machine automatically transits, the signature changes accordingly. KISS random number generator is used as the signature generating algorithm, which makes the state machine very small and fast and requires very low management costs. APPA has an intra-AS (autonomous system) level and an inter-AS level. In the intra-AS level, signatures are tagged into each departing packet at the host and verified at the gateway to achieve finer-grained anti-spoofing than ingress filtering. In the inter-AS level, signatures are tagged at the source AS border router and verified at the destination AS border router to achieve prefix-level anti-spoofing, and the automatic state machine enables the peers to change signatures without negotiation which makes APPA attack-resilient compared with the spoofing prevention method. The results show that the two levels are both incentive for deployment, and they make APPA an integrated anti-spoofing solution. A signature-and-verification-based method, automatic peer-to-peer anti-spoofing (APPA), is proposed to prevent IP source address spoofing. In this method, signatures are tagged into the packets at the source peer, and verified and removed from the verification peer where packets with incorrect signatures are filtered. A unique state machine, which is used to generate signatures, is associated with each ordered pair of APPA peers. generator makes use of the signature generator algorithm, which makes the state machine very small and fast and requires very low management costs. signatures are tagged into each departing packet at the host and verified at the gateway to achieve finer-grained anti-spoofing than ingress filtering. In the inter-AS level, signatures are tagged at the source AS border router a nd verified at the destination AS border router to achieve prefix-level anti-spoofing, and the automatic state machine enables the peers to change signatures without negotiation which makes APPA attack-resilient compared with the spoofing prevention method. The results show that the two levels are both incentive for deployment, and they make APPA an integrated anti-spoofing solution.
其他文献
美国亚利桑那州大学著名心理学教授盖里·希瓦兹历经20多年调查研究后宣称,至少有1/10的患者在器官移植后会性格大变,也就是:“继承”了器官捐赠者的性格。盖里·希瓦兹教授
心理防御是一种潜意识范围的心理保护机制,而心理应对则是属于意识活动内的心理应付措施,两者之间相互关联,互为补充,有利于维护和保持心理健康。现摘其常用者介绍如下。1.升
在我们的传统文化中,对情绪有很深的误解。认为产生情绪对一个人的成熟度、修养有所损伤。所以,希望人们最好不要“有”情绪。其实,情绪是人类非常自然的反应状态。当有危险
以下八道题,测试你在现实中的应变能力:1.你骑车闯红灯,被警察叫住;后者知道你急着要赶路,却故意拖延时间,这时你:A、急得满头大汗,不知怎么办才好B、十分友好地、平静地向警
Nautronix有限公司及WetPC Pty有限公司开发的反水雷作战系统样机包括水下电脑SeaSlate及水下数据通讯系统WetCom两部分。电脑由5按钮小键盘及新颖“Kordic”图形用户接口控
在计算机网络知识日益普及,网络技术应用水平不断提高的趋势下,校园网已经成为推动学校信息化建设的基本平台,在教学现代化、信息化改革方面起到了举足轻重的作用。本文以黔
据《简氏国际海军》2002.107(6)报道:丹麦海军材料司令部已为丹麦海军采购了Anteon国际公司的A/N37U-1扫雷系统,合同价1580万美元。Anteon公司将在四年间改进美国海军正在使
都市白领自己最了解,在表面风光无限的高薪背后,要承受多么巨大的压力。如果没有几招对付压力的“秘笈”,必定难以每天面对苛刻的老板、狡诈的同事、强劲的对手以及紧张的工
和鹰正以3D技术打通服装领域全渠道。近日,由上海和鹰机电科技股份有限公司独家冠名赞助、中国商业联合会及中国百货商业协会联合主办的中国青年时装周2014年新闻发布会在京
[美国《每日防务》2 0 0 3年 4月 1 6日报道 ] BAE公司官员称 ,洛克希德·马丁公司F 35“联合攻击机”(JSF)使用的武器将达到“战斧”导弹标准。BAE公司防务系统副总裁称 :J