【24h】

A Scalable Method to Protect From IP Spoofing

机译:一种可扩展的方法,可防止IP欺骗

获取原文

摘要

Denial of Service (DoS) attacks present a serious problem for Internet communications. The problem is aggravated when the attacker(s) spoof their IP addresses. The Implicit Token Scheme (ITS), presented in [5], is an efficient method to defend against IP spoofing. ITS, however, requires perimeter routers to maintain state information for thousands of simultaneous connections. In this paper we add a component to ITS to improve its scalability using Bloom filters. It is found that implementing ITS using Bloom filters is simple, saves a substantial amount of router memory, and does not impose large strain on routers. The efficiency of the method is demonstrated through simulations by using real-world Internet data.
机译:拒绝服务(DOS)攻击对互联网通信提出了一个严重的问题。当攻击者欺骗其IP地址时,问题会加剧。 [5]中提出的隐式令牌计划(其)是防御IP欺骗的有效方法。但是,它需要周边路由器维护数千个同时连接的状态信息。在本文中,我们将一个组件添加到它以通过绽放过滤器提高其可扩展性。有人发现,使用绽放过滤器实现其简单,可节省大量的路由器内存,并且不会对路由器强加大应变。通过使用现实世界的互联网数据,通过模拟来证明该方法的效率。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号