首页> 外文期刊>清华大学学报(英文版) >Preventing IP Source Address Spoofing: A Two-Level,State Machine-Based Method
【24h】

Preventing IP Source Address Spoofing: A Two-Level,State Machine-Based Method

机译:防止IP源地址欺骗:基于状态机的两级方法

获取原文
获取原文并翻译 | 示例
       

摘要

A signature-and-verification-based method, automatic peer-to-peer anti-spoofing (APPA), is pro-posed to prevent IP source address spoofing. In this method, signatures are tagged into the packets at the source peer, and verified and removed at the verification peer where packets with incorrect signatures are filtered. A unique state machine, which is used to generate signatures, is associated with each ordered pair of APPA peers. As the state machine automatically transits, the signature changes accordingly. KISS ran-dom number generator is used as the signature generating algorithm, which makes the state machine very small and fast and requires very low management costs. APPA has an intre-AS (autonomous system) level and an inter-AS level. In the intra-AS level, signatures are tagged into each departing packet at the host and verified at the gateway to achieve finer-grained anti-spoofing than ingress filtering. In the inter-AS level, signatures are tagged at the source AS border router and verified at the destination AS border muter to achieve prefix-level anti-spoofing, and the automatic state machine enables the peers to change signatures without negotiation which makes APPA attack-resilient compared with the spoofing prevention method. The results show that the two levels are both incentive for deployment, and they make APPA an integrated anti-spoofing solution.
机译:基于签名和验证的方法,自动对等对等反欺骗(APPA),可以采用防止IP源地址欺骗。在此方法中,签名被标记为源对等体的数据包,并在验证对等体处验证和删除,其中过滤具有错误签名的数据包。用于生成签名的唯一状态机与每个有序的APPA对等体相关联。由于状态机自动运输,签名相应地变化。 Kiss RAN-DOM数发电机用作签名生成算法,使状态机非常小且快速,需要非常低的管理成本。 Appa具有英式(自主系统)级别和互等级别。在AS级别的级别中,签名被标记为主机的每个离散数据包,并在网关处验证,以实现比入口滤波更精细的防欺骗。在互等级别中,签名在源处于边界路由器标记,并在目的地验证为边界变介,以实现前缀级防欺骗,并且自动状态机使同行能够在没有协商的情况下更改签名,这使得APPA攻击会更改签名 - 与欺骗预防方法相比。结果表明,两个级别都是部署的激励,并且它们使APPA成为一个集成的防欺骗解决方案。

著录项

  • 来源
    《清华大学学报(英文版)》 |2009年第4期|413-422|共10页
  • 作者单位

    Tsinghua National Laboratory for Information Science and Technology, Network Research Center,Tsinghua University, China Education and Research Network (CERNET), Beijing 100084, China;

    Tsinghua National Laboratory for Information Science and Technology, Network Research Center,Tsinghua University, China Education and Research Network (CERNET), Beijing 100084, China;

    Tsinghua National Laboratory for Information Science and Technology, Network Research Center,Tsinghua University, China Education and Research Network (CERNET), Beijing 100084, China;

    Tsinghua National Laboratory for Information Science and Technology, Network Research Center,Tsinghua University, China Education and Research Network (CERNET), Beijing 100084, China;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 chi
  • 中图分类 计算技术、计算机技术;
  • 关键词

获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号