期刊文献+

基于自治域防御联盟源宣告的域间源地址验证 被引量:1

Inter-AS source address validation based on source declaration and AS alliance
原文传递
导出
摘要 针对国际互联网工程任务组IETF源地址验证增强SAVI工作组重点解决了接入网的IP源地址验证,而自治域间的源地址验证仍然面临挑战的问题,以入口和出口过滤(ingress/egress filtering)防御技术为基础,提出了一种基于自治域防御联盟的域间源地址验证系统方案.该方案通过设计特定的源宣告方式及相关路由策略,确立了联盟成员的验证规则配置形式,在保证方案轻量性的基础上提升了原入口和出口过滤技术的防御性能;着重研究了自治域防御联盟的源宣告策略,针对多路径和误宣告现象引发的回流误判提出了解决方法,证明了以自治域防御联盟为单位的过滤技术具备有效的域间源地址验证能力. To solve the problem that when IETF(Internet engineering task force)SAVI(source address validation improvement)working group focuses on solving the problem of source address validation in access network,validation among AS(autonomous systems)still faces enormous challenges,based on Ingress/Egress Filtering technology,a alliance system was proposed to upgrade the capability in inter-AS source validation.By designing the source declaration method and routing policies,related configurations were put forwarded for each AS in alliance to enhance its filtering performance with lightweight costs.By exploring the phenomenon of multi-path and declaration mistake,the study of the policy in source declaration could not only avoids the potential false positive,but also affirm the feasibility in inter-AS source address validation for AS alliance based on filtering technologies.
作者 贾溢豪 任罡 刘莹 Jia Yihao Ren Gang Liu Ying(Department of Computer Science and Technology Tsinghua National Laboratory for Information Science and Technology Institute for Network Sciences and Cyberspace, Tsinghua University, Beijing 100084, China)
出处 《华中科技大学学报(自然科学版)》 EI CAS CSCD 北大核心 2016年第11期11-15,共5页 Journal of Huazhong University of Science and Technology(Natural Science Edition)
基金 国家自然科学基金资助项目(NSFC61402257) 清华大学自主科研资助项目(2014z21051)
关键词 分布式拒绝服务攻击 IP源地址验证 自治域间 网络安全 源宣告 distributed denial of service attack(DDoS) IP source address validation inter-AS internet security source declaration
  • 相关文献

参考文献2

二级参考文献45

  • 1Koponen T, Shenker S, Balakrishnan H, et al. Architecting for innovation. ACM SIGCOMM Computer Communication Review, 2011, 41(3) 24-36.
  • 2Faloutsos M, Faloutsos P, Faloutsos C. On power law relationships of the internet topology. ACM SIGCOMM Computer Communication Review, 1999, 29(4): 251-262.
  • 3Albert R, Jeong H, Barabfisi A L. Error and attack tolerance of complex networks. Nature, 2000, 406(6794) I 378-382.
  • 4Watts D J, Strogatz S H. Collective dynamics of 'small-world' networks. Nature, 1998, 393(6684): 440-442.
  • 5Gao L. On inferring autonomous system relationships in the Internet. IEEE/ACM Transactions on Networking (TON), 2001, 9(6): 733-745.
  • 6Subramanian L, Agarwal S, Rexford J, et al. Characterizing the Internet hierarchy from multiple vantage points//Pro- ceedings of the INFOCOM 2002. 21st Annual Joint Confer- ence of the IEEE Computer and Communications Societies. New York, USA, 2002, 2:618-627.
  • 7Erlebach T, Hall A, Schank T. Classifying customer provi relationships in the Internet. Swiss Federal Institute[ T0enology, Computer Engineering and Networks Laborator].
  • 8Battista G D, Patrignani M, Pizzonia M. Computing the types o{ the relationships between autonomous systems// Proceedings of the INFOCOM 2003. 22nd Annual Joint Con- ference of the IEEE Computer and Communications Societies. San Francisco, USA, 2003, 1:156-165.
  • 9Dimitropoulos X, Krioukov D, Fomenkov M, et al. AS relationships: inference and validation. ACM SIGCOMM Computer Communication Review, 2007, 37( 1): 29-40.
  • 10Mao Z M, Qiu L, Wang J, et al. On AS-level path inference. ACM SIGMETRICS Performance Evaluation Review, 2005, 33(1): 339 a49.

共引文献61

同被引文献1

引证文献1

二级引证文献4

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部