DocumentCode
2843674
Title
A two-level source address spoofing prevention based on automatic signature and verification mechanism
Author
Shen, Yan ; Bi, Jun ; Wu, Jianping ; Liu, Qiang
Author_Institution
Network Res. Center, Tsinghua Univ., Beijing
fYear
2008
fDate
6-9 July 2008
Firstpage
392
Lastpage
397
Abstract
IP source address spoofing is used by DDoS and DrDoS attacks in the Internet. This paper presents a signature-and-verification based IP spoofing prevention method, automatic peer-to-peer based anti-spoofing method (APPA). APPA has two levels: intra-AS (autonomous system) level and inter-AS level. In the intra-AS level, the end host tags a one-time key into each outgoing packet and the gateway at the AS border verifies the key. In inter-AS level, the gateway at the AS border tags a periodically changed key into the leaving packet and the gateway at border of the destination AS verifies and removes the key. The most prominent characteristic of APPA is the automatically synchronizing state-machine, which is used to update keys automatically and effectively. The benefits of APPA are: (1) preventing IP address spoofing strictly, end systems canpsilat even spoof addresses in the same AS or subnet, (2) providing very low running and management costs, (3) supporting anti-replay attacks and incremental deployment.
Keywords
finite state machines; peer-to-peer computing; telecommunication security; IP spoofing prevention method; anti-replay attacks; automatic peer-to-peer based anti-spoofing method; automatic signature and verification mechanism; automatically synchronizing state-machine; inter-autonomous system; intra-autonomous system; source address spoofing prevention; Authentication; Bismuth; Computer crime; Costs; Information filtering; Information filters; Internet; Peer to peer computing; Scanning probe microscopy; Unsolicited electronic mail;
fLanguage
English
Publisher
ieee
Conference_Titel
Computers and Communications, 2008. ISCC 2008. IEEE Symposium on
Conference_Location
Marrakech
ISSN
1530-1346
Print_ISBN
978-1-4244-2702-4
Electronic_ISBN
1530-1346
Type
conf
DOI
10.1109/ISCC.2008.4625684
Filename
4625684
Link To Document