Controlling IP spoofing through interdomain packet filters

被引:57
作者
Duan, Zhenhai [1 ]
Yuan, Xin [1 ]
Chandrashekar, Jaideep [2 ]
机构
[1] Florida State Univ, Dept Comp Sci, Tallahassee, FL 32306 USA
[2] Intel Res CTL, Santa Clara, CA 95054 USA
关键词
IP spoofing; DDoS; BGP; network-level security and protection; routing protocols;
D O I
10.1109/TDSC.2007.70224
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
The Distributed Denial-of-Service (DDoS) attack is a serious threat to the legitimate use of the Internet. Prevention mechanisms are thwarted by the ability of attackers to forge or spoof the source addresses in IP packets. By employing IP spoofing, attackers can evade detection and put a substantial burden on the destination network for policing attack packets. In this paper, we propose an interdomain packet filter (IDPF) architecture that can mitigate the level of IP spoofing on the Internet. A key feature of our scheme is that it does not require global routing information. IDPFs are constructed from the information implicit in Border Gateway Protocol (BGP) route updates and are deployed in network border routers. We establish the conditions under which the IDPF framework correctly works in that it does not discard packets with valid source addresses. Based on extensive simulation studies, we show that, even with partial deployment on the Internet, IDPFs can proactively limit the spoofing capability of attackers. In addition, they can help localize the origin of an attack packet to a small number of candidate networks.
引用
收藏
页码:22 / 36
页数:15
相关论文
共 33 条
  • [1] [Anonymous], P IEEE S SEC PRIV
  • [2] [Anonymous], P ACM SIGCOMM
  • [3] [Anonymous], 1995, BORDER GATEWAY PROTO
  • [4] Baker F, 1995, 1812 RFC
  • [5] BEVERLY R, 2005, P 1 USENIX STEPS RED
  • [6] BREMLERBARR A, 2005, P IEEE INFOCOM
  • [7] *CERT ADV, 1996, TCP SYN FLOOD IP SPO
  • [8] Chandrashekar J., 2005, P IEEE INFOCOM
  • [9] *CISC SYST, 2007, UN REV PATH FORW LOO
  • [10] DIMITROPOULOS X, 2005, P 6 INT WORKSH PASS