首页> 外文会议>International Conference on Passive and Active Network Measurement >Don't Forget to Lock the Front Door! Inferring the Deployment of Source Address Validation of Inbound Traffic
【24h】

Don't Forget to Lock the Front Door! Inferring the Deployment of Source Address Validation of Inbound Traffic

机译:别忘了锁定前门!推断出源地址验证入站流量的部署

获取原文

摘要

This paper concerns the problem of the absence of ingress filtering at the network edge, one of the main causes of important network security issues. Numerous network operators do not deploy the best current practice-Source Address Validation (SAV) that aims at mitigating these issues. We perform the first Internet-wide active measurement study to enumerate networks not filtering incoming packets by their source address. The measurement method consists of identifying closed and open DNS resolvers handling requests coming from the outside of the network with the source address from the range assigned inside the network under the test. The proposed method provides the most complete picture of the inbound SAV deployment state at network providers. We reveal that 32 673 Autonomous Systems (ASes) and 197 641 Border Gateway Protocol (BGP) prefixes are vulnerable to spoofing of inbound traffic. Finally, using the data from the Spoofer project and performing an open resolver scan, we compare the filtering policies in both directions.
机译:本文涉及在网络边缘缺乏入口滤波的问题,是重要网络安全问题的主要原因之一。众多网络运营商不部署最佳的当前练习源地址验证(SAV),旨在缓解这些问题。我们执行第一个互联网范围的主动测量研究,以枚举网络不通过其源地址过滤传入数据包。测量方法包括识别关闭的关闭和打开DNS解析器,处理来自网络的从网络的外部的请求从网络中的网络中分配的范围。该方法在网络提供商处提供了入站SAV部署状态的最完整图片。我们揭示了32个673个自治系统(ASES)和197 641边界网关协议(BGP)前缀容易受到入站流量的欺骗。最后,使用来自SupOuder项目的数据并执行开放式解析器扫描,我们将过滤策略进行比较在两个方向上。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号