Building a next generation Internet with source address validation architecture

被引:0
|
作者
WU JianPing1
2 Department of Electronic Engineering
3 Tsinghua National Laboratory for Information Science and Technology(TNList)
机构
基金
中国国家自然科学基金;
关键词
IP source address validation; network architecture; network security;
D O I
暂无
中图分类号
TP393.02 [];
学科分类号
摘要
The IP packet forwarding of current Internet is mainly destination based. In the forwarding process,the source IP address is not checked in most cases.This causes serious security,management and accounting problems. Based on the drastically increased IPv6 address space,a "source address validation architecture"(SAVA) is proposed in this paper,which can guarantee that every packet received and forwarded holds an authenticated source IP address. The design goals of the architecture are lightweight,loose coupling,"multi-fence support" and incremental deployment. This paper discusses the design and implementation for the architecture,including inter-AS,intra-AS and local subnet. The performance and scalability of SAVA are described. This architecture is deployed into the CNGI-CERNET2 infrastructure―a large-scale native IPv6 backbone network of the China Next Generation Internet project. We believe that the SAVA will help the transition to a new,more secure and dependable Internet.
引用
收藏
页码:1681 / 1691
页数:11
相关论文
共 50 条
  • [22] Hybrid Transition Mechanism for MILSA Architecture for the Next Generation Internet
    Pan, Jianli
    Paul, Subharthi
    Jain, Raj
    Xu, Xiaohu
    2009 IEEE GLOBECOM WORKSHOPS, 2009, : 532 - +
  • [23] A differentiated services architecture for multimedia streaming in next generation Internet
    Hou, YT
    Wu, DP
    Li, B
    Hamada, T
    Ahmad, I
    Chao, HJ
    COMPUTER NETWORKS, 2000, 32 (02) : 185 - 209
  • [24] ASTVA: DDoS-limiting Architecture for Next Generation Internet
    Wei Wei
    Xia Yingjie
    Dong Yabo
    AUTOMATIC MANUFACTURING SYSTEMS II, PTS 1 AND 2, 2012, 542-543 : 1275 - +
  • [25] MPFS: A truly scalable router architecture for next generation Internet
    Sun ZhiGang
    Dai Yi
    Gong ZhengHu
    SCIENCE IN CHINA SERIES F-INFORMATION SCIENCES, 2008, 51 (11): : 1761 - 1771
  • [26] System architecture of a multimedia streaming server for the next generation Internet
    Park, CW
    Kim, SW
    Park, JW
    EMBEDDED AND UBIQUITOUS COMPUTING, PROCEEDINGS, 2004, 3207 : 662 - 671
  • [27] MPFS: A truly scalable router architecture for next generation Internet
    ZhiGang Sun
    Yi Dai
    ZhengHu Gong
    Science in China Series F: Information Sciences, 2008, 51 : 1761 - 1771
  • [28] Network Hygiene, Incentives, and Regulation: Deployment of Source Address Validation in the Internet
    Luckie, Matthew
    Beverly, Robert
    Koga, Ryan
    Keys, Ken
    Kroll, Joshua A.
    Claffy, K.
    PROCEEDINGS OF THE 2019 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY (CCS'19), 2019, : 465 - 480
  • [29] A Novel Identity-based Network Architecture for Next Generation Internet
    Martinez-Julia, Pedro
    Gomez-Skarmeta, Antonio F.
    JOURNAL OF UNIVERSAL COMPUTER SCIENCE, 2012, 18 (12) : 1643 - 1661
  • [30] SIP over an identifier/locator splitted next generation internet architecture
    Rothenberg, Christian Esteve
    Wong, Walter
    Verdi, Fabio L.
    Magalhaes, Mauricio F.
    10TH INTERNATIONAL CONFERENCE ON ADVANCED COMMUNICATION TECHNOLOGY, VOLS I-III: INNOVATIONS TOWARD FUTURE NETWORKS AND SERVICES, 2008, : 621 - 626