首页> 外文会议>Computational Science - ICCS 2007 pt.4; Lecture Notes in Computer Science; 4490 >An Authentication Based Source Address Spoofing Prevention Method Deployed in IPv6 Edge Network
【24h】

An Authentication Based Source Address Spoofing Prevention Method Deployed in IPv6 Edge Network

机译:IPv6边缘网络中部署的基于身份验证的源地址欺骗防范方法

获取原文
获取原文并翻译 | 示例

摘要

In today's Internet routing architecture, the router doesn't validate the correctness of the source address carried in the packet, nor keep the state information when forwarding the packet. Thus the DDoS attacks with spoofed IP source address can cause security problems. In this paper, we aim to prevent the attackers from attacking somewhere outside the IPv6 edge network with forged source address in the fine granularity. The proposed methods include source address authentication by using session key and hash digest algorithm, and replay attack prevention by combining the sequence number method and the timestamp method. This paper presents the algorithm design and evaluates its feasibility and correctness by simulation experiments.
机译:在当今的Internet路由体系结构中,路由器既不验证数据包中携带的源地址的正确性,也不在转发数据包时保留状态信息。因此,具有欺骗性IP源地址的DDoS攻击可能导致安全问题。在本文中,我们旨在防止攻击者以精细的粒度伪造源地址攻击IPv6边缘网络外部的某个地方。所提出的方法包括使用会话密钥和哈希摘要算法进行源地址认证,以及通过结合序列号方法和时间戳方法来防止重放攻击。本文介绍了算法设计,并通过仿真实验对其可行性和正确性进行了评估。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号