DocumentCode
13987
Title
SAVI: The IETF standard in address validation
Author
Bagnulo, Marcelo ; Garcia-Martinez, A.
Author_Institution
Univ. Carlos III de Madrid, Leganés, Spain
Volume
51
Issue
4
fYear
2013
fDate
Apr-13
Firstpage
66
Lastpage
73
Abstract
In this article we describe Source Address Validation Implementation (SAVI), a security architecture being standardized by the IETF to prevent source address spoofing within a link. SAVI devices, usually layer 2 switches, create bindings between the IP address of a node and a property of the host¿s network attachment, such as the port through which the packet is received. Bindings are created by monitoring the packet exchange associated with IP address configuration mechanisms such as DHCP, SLAAC, or SEND. SAVI devices filter out packets whose source IP address does not match with an existing binding.
Keywords
IP networks; Internet; computer network security; switching networks; telecommunication standards; DHCP; IETF standard; IP address Validation; SAVI filter device; SEND; SLAAC; host network attachment; layer 2 switch; packet exchange; security architecture; source address validation implementation; Databases; Digital audio broadcasting; Filtering; IP networks; Monitoring; Network security; Ports (Computers); Protocols; Servers; System analysis and design;
fLanguage
English
Journal_Title
Communications Magazine, IEEE
Publisher
ieee
ISSN
0163-6804
Type
jour
DOI
10.1109/MCOM.2013.6495763
Filename
6495763
Link To Document