首页> 外文会议>International IFIP-TC6 Networking Conference; 20050502-06; Waterloo(CA) >LIPS: Lightweight Internet Permit System for Stopping Unwanted Packets
【24h】

LIPS: Lightweight Internet Permit System for Stopping Unwanted Packets

机译:LIPS:用于阻止有害数据包的轻量级Internet许可系统

获取原文
获取原文并翻译 | 示例

摘要

In this paper, we propose a Lightweight Internet Permit System (LIPS) that provides a lightweight, scalable packet authentication mechanism for ensuring traffic-origin accountability. LIPS is a simple extension of IP, in which each packet carries an access permit issued by its destination host or gateway, and the destination verifies the access permit to determine if a packet is accepted or dropped. We will first present the design and the prototype implementation of LIPS on Linux 2.4 kernel. We then use analysis, simulations, and experiments to show how LIPS can effectively prevent protected critical servers and links from being flooded by unwanted packets with negligible overheads. We propose LIPS as an domain-to-domain approach to stop unwanted attacks, without requiring broad changes in backbone networks as other approaches. Therefore, LIPS is incrementally deployable in a large scale on common platforms with minor software patches.
机译:在本文中,我们提出了一种轻量级Internet许可系统(LIPS),该系统提供了一种轻量级,可扩展的数据包身份验证机制,以确保流量来源的责任制。 LIPS是IP的简单扩展,其中每个数据包都携带由其目标主机或网关发出的访问许可,并且目标验证访问许可以确定是否接受或丢弃了一个数据包。我们将首先介绍Linux 2.4内核上LIPS的设计和原型实现。然后,我们使用分析,模拟和实验来展示LIPS如何有效地防止受保护的关键服务器和链接被开销很小的不想要的数据包淹没。我们建议使用LIPS作为域到域的方法来阻止不必要的攻击,而无需像其他方法那样在骨干网中进行广泛的更改。因此,LIPS可以在具有次要软件补丁的通用平台上大规模增量部署。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号