• DocumentCode
    1812635
  • Title

    Spoofing prevention method

  • Author

    Bremler-Barr, Anat ; Levy, Hanoch

  • Author_Institution
    Interdisciplinary Center Herzliya, Israel
  • Volume
    1
  • fYear
    2005
  • fDate
    13-17 March 2005
  • Firstpage
    536
  • Abstract
    A new approach for filtering spoofed IP packets, called spoofing prevention method (SPM), is proposed. The method enables routers closer to the destination of a packet to verify the authenticity of the source address of the packet. This stands in contrast to standard ingress filtering which is effective mostly at routers next to the source and is ineffective otherwise. In the proposed method a unique temporal key is associated with each ordered pair of source destination networks (AS´s, autonomous systems). Each packet leaving a source network S is tagged with the key K(S, D), associated with (S, D), where D is the destination network. Upon arrival at the destination network the key is verified and removed. Thus the method verifies the authenticity of packets carrying the address s which belongs to network S. An efficient implementation of the method, ensuring not to overload the routers, is presented. The major benefits of the method are the strong incentive it provides to network operators to implement it, and the fact that the method lends itself to stepwise deployment, since it benefits networks deploying the method even if it is implemented only on parts of the Internet. These two properties, not shared by alternative approaches, make it an attractive and viable solution to the packet spoofing problem.
  • Keywords
    IP networks; Internet; information filtering; telecommunication network routing; telecommunication security; Internet; autonomous system; source destination network; spoofed IP packet filtering; spoofing prevention method; temporal key; Computer crime; Computer hacking; Costs; IP networks; Information filtering; Information filters; Law enforcement; Scanning probe microscopy; Telecommunication traffic; Web and internet services;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    INFOCOM 2005. 24th Annual Joint Conference of the IEEE Computer and Communications Societies. Proceedings IEEE
  • ISSN
    0743-166X
  • Print_ISBN
    0-7803-8968-9
  • Type

    conf

  • DOI
    10.1109/INFCOM.2005.1497921
  • Filename
    1497921