DocumentCode :
1976358
Title :
SAVE: source address validity enforcement protocol
Author :
Li, Jun ; Mirkovic, Jelena ; Wang, Mengqiu ; Reiher, Peter ; Zhang, Lixia
Author_Institution :
University of California
Volume :
3
fYear :
2002
fDate :
23-27 June 2002
Firstpage :
1557
Lastpage :
1566
Abstract :
Forcing all IP packets to carry correct source addresses can greatly help network security, attack tracing, and network problem debugging. However, due to asymmetries in today´s Internet routing, routers do not have readily available information to verify the correctness of the source address for each incoming packet. In this paper we describe a new protocol, named SAVE, that can provide routers with the information needed for source address validation. SAVE messages propagate valid source address information from the source location to all destinations, allowing each router along the way to build an incoming table that associates each incoming interface of the router with a set of valid source address blocks. This paper presents the protocol design and evaluates its correctness and performance by simulation experiments. The paper also discusses the issues of protocol security, the effectiveness of partial SAVE deployment, and the handling of unconventional forms of network routing, such as mobile IP and tunneling.
Keywords :
Computer crime; Debugging; Information filtering; Information filters; Information security; Internet; Position measurement; Routing protocols; Traffic control; Tunneling;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
INFOCOM 2002. Twenty-First Annual Joint Conference of the IEEE Computer and Communications Societies. Proceedings. IEEE
Conference_Location :
New York, NY, USA
ISSN :
0743-166X
Print_ISBN :
0-7803-7476-2
Type :
conf
DOI :
10.1109/INFCOM.2002.1019407
Filename :
1019407
Link To Document :
بازگشت