Loading [a11y]/accessibility-menu.js
A two-level source address spoofing prevention based on automatic signature and verification mechanism | IEEE Conference Publication | IEEE Xplore

A two-level source address spoofing prevention based on automatic signature and verification mechanism


Abstract:

IP source address spoofing is used by DDoS and DrDoS attacks in the Internet. This paper presents a signature-and-verification based IP spoofing prevention method, automa...Show More

Abstract:

IP source address spoofing is used by DDoS and DrDoS attacks in the Internet. This paper presents a signature-and-verification based IP spoofing prevention method, automatic peer-to-peer based anti-spoofing method (APPA). APPA has two levels: intra-AS (autonomous system) level and inter-AS level. In the intra-AS level, the end host tags a one-time key into each outgoing packet and the gateway at the AS border verifies the key. In inter-AS level, the gateway at the AS border tags a periodically changed key into the leaving packet and the gateway at border of the destination AS verifies and removes the key. The most prominent characteristic of APPA is the automatically synchronizing state-machine, which is used to update keys automatically and effectively. The benefits of APPA are: (1) preventing IP address spoofing strictly, end systems canpsilat even spoof addresses in the same AS or subnet, (2) providing very low running and management costs, (3) supporting anti-replay attacks and incremental deployment.
Date of Conference: 06-09 July 2008
Date Added to IEEE Xplore: 16 September 2008
ISBN Information:
Print ISSN: 1530-1346
Conference Location: Marrakech

Contact IEEE to Subscribe

References

References is not available for this document.