Internet source address verification method based on synchronization and dynamic filtering in address domain

Autor: Dan LI, Lancheng QIN, Jianping WU, Yingying SU, Mingwei XU, Xingang SHI, Yunan GU, Tao LIN
Jazyk: čínština
Rok vydání: 2020
Předmět:
Zdroj: Dianxin kexue, Vol 36, Pp 21-28 (2020)
Druh dokumentu: article
ISSN: 1000-0801
DOI: 10.11959/j.issn.1000-0801.2020289
Popis: At the beginning of the design of the Internet architecture,it assumed that all network members were trusted,and did not fully consider the security threat brought by the untrusted network members.For a long time,routers only forward packets based on the destination IP address of the packet,and do not carry out any verification on the source IP address of the packet.The lack of packet level authenticity on the Internet results in the header being maliciously altered.A real source address verification mechanism with routing synchronization and dynamic filtering were proposed.This mechanism constructs the filter table based on the prefix-topology mapping synchronization,the problem of inconsistent state between the filter table and the route caused by routing asymmetry were solved,false positives and false negatives was avoided,and a low-overhead and low-latency source address verification of the IP address prefix level granularity in the address domain were realized.
Databáze: Directory of Open Access Journals