【24h】

A trust-based approach against IP-spoofing attacks

机译:基于信任的IP欺骗攻击方法

获取原文

摘要

IP-spoofing attacks remain one of the most damaging attacks in which an attacker replaces the original source IP address with a new one. Using the existing attacking tools to launch IP spoofing attacks, an attacker can now easily compromise access routers and not only the end-hosts. In this paper, we propose a trust-based approach using a Bayesian inference model that evaluates the trustworthiness of an access router with regards to forwarding packets without modifying their source IP address. The trust values for the access routers is computed by a judge router that samples all traffic being forwarded by the access routers. The simulation results show that our approach effectively detects malicious access routers. The results also show that our approach has a low impact on the network performance when no attack is present, and that it introduces little overhead traffic.
机译:IP欺骗攻击仍然是最具破坏性的攻击之一,攻击者使用新的IP地址替换原始的源IP地址。使用现有的攻击工具发起IP欺骗攻击,攻击者现在可以轻松地破坏访问路由器,而不仅仅是终端主机。在本文中,我们提出了一种使用贝叶斯推理模型的基于信任的方法,该模型评估了访问路由器在转发数据包时无需修改其源IP地址的可信度。接入路由器的信任值由判断路由器计算,该路由器对接入路由器转发的所有流量进行采样。仿真结果表明,我们的方法有效地检测了恶意访问路由器。结果还表明,当不存在攻击时,我们的方法对网络性能的影响很小,并且引入的开销很少。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号