An Authentication Based Source Address Spoofing Prevention Method Deployed in IPv6 Edge Network

  • Authors:
  • Lizhong Xie;Jun Bi;Jianpin Wu

  • Affiliations:
  • Network Research Center, Tsinghua University, Beijing, 100084, China;Network Research Center, Tsinghua University, Beijing, 100084, China;Network Research Center, Tsinghua University, Beijing, 100084, China

  • Venue:
  • ICCS '07 Proceedings of the 7th international conference on Computational Science, Part IV: ICCS 2007
  • Year:
  • 2007

Quantified Score

Hi-index 0.00

Visualization

Abstract

In today's Internet routing architecture, the router doesn't validate the correctness of the source address carried in the packet, nor keep the state information when forwarding the packet. Thus the DDoS attacks with spoofed IP source address can cause security problems. In this paper, we aim to prevent the attackers from attacking somewhere outside the IPv6 edge network with forged source address in the fine granularity. The proposed methods include source address authentication by using session key and hash digest algorithm, and replay attack prevention by combining the sequence number method and the timestamp method. This paper presents the algorithm design and evaluates its feasibility and correctness by simulation experiments.