首页> 外文会议>IEEE International Workshop on Local Metropolitan Area Networks >An inter-AS path vector filter: towards elimination of false negatives
【24h】

An inter-AS path vector filter: towards elimination of false negatives

机译:一个互通路径矢量滤波器:消除错误的底片

获取原文

摘要

IP spoofing based attacks remains a serious and open security problem due to the fact that the current Internet implements no source address authentication mechanisms. A series of anti-spoofing practices have long been proposed while their actual implementation seems far from satisfactory. Route based filters were extensively studied in the design of Inter-AS source address validation methods. Traditional route based filters only use route direction information to establish filtering rules, causing inherited fake negatives. A novel inter-AS filter based on route path vector is proposed to reduce or even eliminate such fake negatives in this article. We name the filter IPVF (Inter-AS Path Vector Filter), which utilizes the route information of both path and distance, exhibits measurable increase in performance and incurs acceptable additional bandwidth cost. Moreover, traditional route based filtering rules is easy to be deduced by attackers. Since the filtering rules of IPVF could change over time by setting parameters, its actual improvement in performance could be exponentially increased.
机译:由于当前的互联网实现没有源地址认证机制,因此基于IP欺骗的攻击仍然是一个严重和开放的安全问题。已经提出了一系列反欺骗实践,而实际实施似乎远非令人满意。在互源地址验证方法的设计中广泛研究了基于路由的过滤器。传统的基于路线的过滤器仅使用路线方向信息来建立过滤规则,导致继承的虚假底片。提出了一种基于路径路径向量的新型滤波器,以减少甚至消除本文中的这种假底部。我们将滤波器IPVF(INTU-AS PATH向量滤波器)命名为使用路径和距离的路径信息,表现出可测量的性能提高,并引用可接受的额外带宽成本。此外,攻击者易于推断出基于路线的过滤规则。由于IPVF的过滤规则可以通过设置参数随时间而变化,因此其性能的实际提高可以是指数增加的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号