Title :
An inter-AS path vector filter: towards elimination of false negatives
Author :
Zhou Zhang ; Ying Liuy ; Jianping Wuy ; Reny, Gang ; Jun Bi
Author_Institution :
Dept. of Comput. Sci. & Technol., Tsinghua Univ., Beijing, China
Abstract :
IP spoofing based attacks remains a serious and open security problem due to the fact that the current Internet implements no source address authentication mechanisms. A series of anti-spoofing practices have long been proposed while their actual implementation seems far from satisfactory. Route based filters were extensively studied in the design of Inter-AS source address validation methods. Traditional route based filters only use route direction information to establish filtering rules, causing inherited fake negatives. A novel inter-AS filter based on route path vector is proposed to reduce or even eliminate such fake negatives in this article. We name the filter IPVF (Inter-AS Path Vector Filter), which utilizes the route information of both path and distance, exhibits measurable increase in performance and incurs acceptable additional bandwidth cost. Moreover, traditional route based filtering rules is easy to be deduced by attackers. Since the filtering rules of IPVF could change over time by setting parameters, its actual improvement in performance could be exponentially increased.
Keywords :
IP networks; Internet; computer network security; telecommunication network routing; IP spoofing based attacks; IPVF filter; Internet; antispoofing practices; bandwidth cost; false negative elimination; interAS path vector filter; interAS source address validation methods; open security problem; route based filters; route direction information; source address authentication mechanisms; IP networks; Information filtering; Internet; Routing; Routing protocols; Security; Filtering; IP Source Address Validation; IP Spoofing;
Conference_Titel :
Local and Metropolitan Area Networks (LANMAN), 2015 IEEE International Workshop on
Conference_Location :
Beijing
DOI :
10.1109/LANMAN.2015.7114734