DocumentCode
1976358
Title
SAVE: source address validity enforcement protocol
Author
Li, Jun ; Mirkovic, Jelena ; Wang, Mengqiu ; Reiher, Peter ; Zhang, Lixia
Author_Institution
University of California
Volume
3
fYear
2002
fDate
23-27 June 2002
Firstpage
1557
Lastpage
1566
Abstract
Forcing all IP packets to carry correct source addresses can greatly help network security, attack tracing, and network problem debugging. However, due to asymmetries in today´s Internet routing, routers do not have readily available information to verify the correctness of the source address for each incoming packet. In this paper we describe a new protocol, named SAVE, that can provide routers with the information needed for source address validation. SAVE messages propagate valid source address information from the source location to all destinations, allowing each router along the way to build an incoming table that associates each incoming interface of the router with a set of valid source address blocks. This paper presents the protocol design and evaluates its correctness and performance by simulation experiments. The paper also discusses the issues of protocol security, the effectiveness of partial SAVE deployment, and the handling of unconventional forms of network routing, such as mobile IP and tunneling.
Keywords
Computer crime; Debugging; Information filtering; Information filters; Information security; Internet; Position measurement; Routing protocols; Traffic control; Tunneling;
fLanguage
English
Publisher
ieee
Conference_Titel
INFOCOM 2002. Twenty-First Annual Joint Conference of the IEEE Computer and Communications Societies. Proceedings. IEEE
Conference_Location
New York, NY, USA
ISSN
0743-166X
Print_ISBN
0-7803-7476-2
Type
conf
DOI
10.1109/INFCOM.2002.1019407
Filename
1019407
Link To Document