IP spoofing hinders the efficiency of DDoS defenses. While recent proposals of IP spoofing prevention mechanisms are weak at filtering spoofing packets due to the complexity in maintaining source IP spaces and the low...IP spoofing hinders the efficiency of DDoS defenses. While recent proposals of IP spoofing prevention mechanisms are weak at filtering spoofing packets due to the complexity in maintaining source IP spaces and the low incentive of deployments. To address this problem,we propose an efficient mechanism to extend the range of inter-domain IP spoofing prevention called MASK. Source MASK nodes inform destination MASK nodes about the source IP spaces and labels of their neighbor Stub-ASes in order to implement the marking and verification of packets towards the Stub-ASes,and limit the number of MASK peers through the propagation of BGP updates so as to reduce the overheads of computing and storing of labels. By utilizing the method of extending the spoofing prevention to Stub-ASes,MASK can not only enlarge the domain of the spoofing prevention service,but also filter spoofing packets in advance. Through analysis and simulations,we demonstrate MASK's accuracy and effectiveness.展开更多
随着空间通信系统的发展,CCSDS建议逐渐成为了空间通信的标准,特别是IP over CCSDS Space Links红皮书提出以后,IP已经成为空间信息系统的标准上层应用。提出了一种天地通信系统CCSDS加速网关的设计实现方法,介绍了基于加速网关的天地...随着空间通信系统的发展,CCSDS建议逐渐成为了空间通信的标准,特别是IP over CCSDS Space Links红皮书提出以后,IP已经成为空间信息系统的标准上层应用。提出了一种天地通信系统CCSDS加速网关的设计实现方法,介绍了基于加速网关的天地通信网络结构,描述了其关键技术实现,最后对提出的设计实现方法在OPNET中进行了仿真验证。OPNET仿真结果表明,该技术大大提高了TCP应用在空间链路上的传输效率,而且在多连接共享带宽时保持了较好的公平性。展开更多
基金the National Basic Research Program of China (973 Program) (Grant Nos. 2003CB314802 and 2005CB321801)
文摘IP spoofing hinders the efficiency of DDoS defenses. While recent proposals of IP spoofing prevention mechanisms are weak at filtering spoofing packets due to the complexity in maintaining source IP spaces and the low incentive of deployments. To address this problem,we propose an efficient mechanism to extend the range of inter-domain IP spoofing prevention called MASK. Source MASK nodes inform destination MASK nodes about the source IP spaces and labels of their neighbor Stub-ASes in order to implement the marking and verification of packets towards the Stub-ASes,and limit the number of MASK peers through the propagation of BGP updates so as to reduce the overheads of computing and storing of labels. By utilizing the method of extending the spoofing prevention to Stub-ASes,MASK can not only enlarge the domain of the spoofing prevention service,but also filter spoofing packets in advance. Through analysis and simulations,we demonstrate MASK's accuracy and effectiveness.
文摘随着空间通信系统的发展,CCSDS建议逐渐成为了空间通信的标准,特别是IP over CCSDS Space Links红皮书提出以后,IP已经成为空间信息系统的标准上层应用。提出了一种天地通信系统CCSDS加速网关的设计实现方法,介绍了基于加速网关的天地通信网络结构,描述了其关键技术实现,最后对提出的设计实现方法在OPNET中进行了仿真验证。OPNET仿真结果表明,该技术大大提高了TCP应用在空间链路上的传输效率,而且在多连接共享带宽时保持了较好的公平性。