首页> 外文期刊>Computer networks >LIPS: A lightweight permit system for packet source origin accountability
【24h】

LIPS: A lightweight permit system for packet source origin accountability

机译:LIPS:一种轻量级的许可证系统,用于数据包源始发问责制

获取原文
获取原文并翻译 | 示例
           

摘要

One of key security issues on the current Internet is unwanted traffic, the forerunner of unauthorized accesses, scans, and attacks. It is vitally important but extremely challenging to fight such unwanted traffic. We need a series of defensive mechanisms to identify unwanted packets, filter them out, and further defeat their associated attacks. In this paper, we propose a lightweight, scalable packet authentication mechanism, named Lightweight Internet Permit System (LIPS), as a first line of defense to effectively filter out the most common forms of unwanted traffic, spoofed and unsolicited packets, such that in-depth security schemes can take care of the remaining issues more efficiently. LIPS is a simple extension of IP, in which each packet carries an access permit issued by its destination host or gateway, and the destination verifies the access permit to determine to accept or drop the packet. LIPS provides preliminary traffic-origin accountability that supports two salient features to confine unwanted traffic: (1) filter out the most common forms of unwanted packets and defeat associated attacks; (2) help us identify compromised hosts/domains such that we are able to build active defense schemes to deal with various attacks through real-time inter-domain collaboration. In this paper, we first present the design and prototype implementation of LIPS on Linux 2.4 kernel, and then use analysis, simulations, and experiments to demonstrate the efficacy of LIPS in protecting critical resources with light overheads.
机译:当前Internet上的关键安全问题之一是不需要的流量,这是未经授权的访问,扫描和攻击的先驱。打击此类不必要的流量至关重要,但极具挑战性。我们需要一系列防御机制来识别不需要的数据包,将其过滤掉,并进一步击败相关的攻击。在本文中,我们提出了一种轻量级的,可扩展的数据包身份验证机制,称为轻量级Internet许可系统(LIPS),它是有效过滤掉最常见形式的有害流量,欺骗性和非请求性数据包的第一道防线,例如深度安全方案可以更有效地解决其余问题。 LIPS是IP的简单扩展,其中每个数据包都携带由其目标主机或网关颁发的访问许可,并且目标验证访问许可以确定是否接受或丢弃该数据包。 LIPS提供了初步的流量起源问责制,它支持两个显着的功能来限制有害流量:(1)过滤掉最常见的有害数据包形式并消除相关的攻击; (2)帮助我们识别受感染的主机/域,以便我们能够建立主动防御方案,以通过实时域间协作来应对各种攻击。在本文中,我们首先介绍Linux 2.4内核上LIPS的设计和原型实现,然后使用分析,模拟和实验来证明LIPS在轻载下保护关键资源的有效性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号