DocumentCode :
3096983
Title :
SAVT: A Practical Scheme for Source Address Validation and Traceback in Campus Network
Author :
Hu, Guangwu ; Wu, Jianping ; Xu, Ke ; Chen, Wenlong
Author_Institution :
Dept. of Comput. Sci. & Technol., Tsinghua Univ., Beijing, China
fYear :
2011
fDate :
July 31 2011-Aug. 4 2011
Firstpage :
1
Lastpage :
8
Abstract :
In current network, as we all know, packets delivered by routers only rely on destination-address-directed forwarding, but their source addresses are not checked. Consequently, this incurs many serious network security breach events which are hard to trackback. Under this situation, a switch (we call it SAVI switch) followed SAVI (Source Address Validation Improvement) framework proposed by IETF was invented which dedicates to resolving this problem in user local subnet. SAVI switch is a direct and very effective anti-spoofing device, but because it just steps into a phase of industrialization and for economical and incremental deployment reasons, these switches are not fully covered in domain. This results in two issues at the same time: 1)how to filter out and abandon those packets whose source IP addresses belong to SAVI switches coverage, but actually not, otherwise, this will severely compromise the SAVI switch access users´ motivation and SAVI´s promotion. 2) how to traceback those packets´ source router-the first hop routers of spoofed packets. In this paper, we present SAVT, a practical and smart scheme for source address validation and traceback in campus network for all outbound packets, it just need less 25% routers as filter router can resolve those two questions in most condition. Experiments illustrate our proposal keeps the promise of practicality, stability and efficiency.
Keywords :
IP networks; computer network security; packet switching; telecommunication network routing; IETF; SAVI promotion; SAVI switch access user motivation; SAVT; antispoofing device; campus network; destination-address-directed forwarding; filter router; network security breach events; source IP addresses; source address traceback; source address validation improvement; user local subnet; Filtering; IP networks; Proposals; Routing protocols; Switches; Topology;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computer Communications and Networks (ICCCN), 2011 Proceedings of 20th International Conference on
Conference_Location :
Maui, HI
ISSN :
1095-2055
Print_ISBN :
978-1-4577-0637-0
Type :
conf
DOI :
10.1109/ICCCN.2011.6005783
Filename :
6005783
Link To Document :
بازگشت