期刊文献+

IPv6网络自治系统间源地址验证技术研究 被引量:3

Inter-AS source address validation on IPv6 network
下载PDF
导出
摘要 现有互联网的寻址体系结构对接收和转发的IP分组的源地址并不进行严格的检查,很容易伪造IP分组的源地址。本文提出了在IPv6网络下在自治系统间实现源地址验证的方法,其对IPv6网络的安全,计费,管理和应用都会有所帮助。针对进行源地址验证的两个自治系统直接互联的情况,提出了基于自治系统互联关系的验证方法,针对进行源地址验证的两个自治系统非直接互联的情况,提出了基于签名的验证方法。本文阐述了其设计,实现,以及在CNGI-CERNEF2,一个大规模纯IPv6主干网上部署的情况。 The current Internet addressing architecture does not verify the source address of a packet received and forwarded.This causes serious security problems.This paper proposed the solutions for Inter-AS source address validation in IPv6 network,which can improve the security of IPv6 network.An AS relation based method is proposed for directly connected AS,and a signature based method is proposed for ASes which are not directly connected.This paper discusses the details of design,implementation and deployment into the CNGI-CERNET2 infrastructure-a large-scale native IPv6 backbone network of the China Next Generation Internet project.
出处 《中国科技论文在线》 CAS 2007年第10期715-719,共5页
基金 国家自然科学基金(90104002) 973计划项目(2003CB314800)
关键词 网络安全 源地址验证 基于自治系统互联关系的自治系统间IP源地址验证 基于签名的自治系统间IP源地址验证 network security source address validation AS relation based Inter-AS source address validation signature based Inter-AS source address validation
  • 相关文献

参考文献10

  • 1Bremler-Barr A,Levy H.Spoofing Prevention Method[]..2005
  • 2Ferguson P,Senie D.Network Ingress Filtering: Defeating Denial of Service Attacks which employ IP Source Address Spoofing[].RFC.2000
  • 3Li J,Mirkovic J,Wang M,et al.SAVE:Source Address Validity Enforcement Protocol[]..2002
  • 4Jin C,Wang H.Hop-count filtering:an effective defense against spoofed DDoS traffic[]..2003
  • 5Snoeren A,Partridge C,Sanchez L.et al.A Hash-based IP traceback[]..2001
  • 6Bellovin S,Leech M,Taylor T.ICMP Traceback messages. IETF Internet Draft,draft-ietf-itrace-03 . 2003
  • 7Lee H,Thing V,Xu Y,et al.ICMP Traceback with Cumulative Path,An Effcient Solution for IP Traceback[].Information and Communications Security.2003
  • 8Savage S,Wetherall D,Karlin A,et al.Pratical network support for IP traceback[]..2000
  • 9Kent S,Atkinson R.RFC2401Security Architecture for The Internet Protocol[]..1998
  • 10PARKK,,LEE H.On the effectiveness ofroute- basedpacket filtering for distributed DoS attack prevention in power- law Internets. Proceedings ofConference on Applications, Technologies, Architectures, and Protocols for Computer Communication (SIGCOMM 2001), Aug 27- 31, 2001 . 2001

同被引文献91

  • 1王晓峰,吴建平,崔勇.互联网IPv6过渡技术综述[J].小型微型计算机系统,2006,27(3):385-395. 被引量:79
  • 2任罡,段海新.973计划“新一代互联网体系结构理论研究”项目之课题四 真实IPv6源地址寻址体系结构研究[J].中国教育网络,2007(5):26-27. 被引量:1
  • 3DEERING S, ttlNDEN R. RFC 2460, Interact protocol version 6 ( IPv6 ) specification [ S]. Fremont : IETF, 1998.
  • 4BRADNER S, MANKIN A. RFC 1752,The recommendation for the IP next generation protocol[ S ]. Fremont : IETF, 1995.
  • 5Commission of the European Communities. Next generation lnternet: priorities for action in migrating to the new Internet protocol IPv6 [ EB/OL ]. ( 2002-02-21 ). http ://www. ipv6tf, org/PublicDocu-ments/com2002 -0096 enO 1. pdf.
  • 6EGEVANG K B, FRANCIS P. RFC 1631, The IP network address translator (NAT) [ S ]. Fremont: IETF, 1994.
  • 7PARK K, LEE H. A proactive approach to distributed DoS attack pre- vention using route-based packet filtering, CSI) TR00-017 [ R]. West Lafayette : Purdue University ,2000.
  • 8LI Jun, SUNG M H, XU Jun, et al. Large-scale IP traceback in high- speed Internet : practical techniques and theoretical foundation [ C ]// Proc of IEEE Symposium on Security and Privacy. 2004:115-129.
  • 9MANKIN A,MASSEY D,WU C L,et al. On design and evaluation of intention-driven ICMP traceback [ C ]//Proc of the 10th IEEE Inter- national Conference on Computer Communications and Networks. New York : IEEE ,2001 : 159-165.
  • 10BELLOVIN S, TAYLOR T. RFC 2026, ICMP traceback messages [ S ]. Fremont : IETF,2003.

引证文献3

二级引证文献8

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部