Title :
SAVT: A Practical Scheme for Source Address Validation and Traceback in Campus Network
Author :
Hu, Guangwu ; Wu, Jianping ; Xu, Ke ; Chen, Wenlong
Author_Institution :
Dept. of Comput. Sci. & Technol., Tsinghua Univ., Beijing, China
fDate :
July 31 2011-Aug. 4 2011
Abstract :
In current network, as we all know, packets delivered by routers only rely on destination-address-directed forwarding, but their source addresses are not checked. Consequently, this incurs many serious network security breach events which are hard to trackback. Under this situation, a switch (we call it SAVI switch) followed SAVI (Source Address Validation Improvement) framework proposed by IETF was invented which dedicates to resolving this problem in user local subnet. SAVI switch is a direct and very effective anti-spoofing device, but because it just steps into a phase of industrialization and for economical and incremental deployment reasons, these switches are not fully covered in domain. This results in two issues at the same time: 1)how to filter out and abandon those packets whose source IP addresses belong to SAVI switches coverage, but actually not, otherwise, this will severely compromise the SAVI switch access users´ motivation and SAVI´s promotion. 2) how to traceback those packets´ source router-the first hop routers of spoofed packets. In this paper, we present SAVT, a practical and smart scheme for source address validation and traceback in campus network for all outbound packets, it just need less 25% routers as filter router can resolve those two questions in most condition. Experiments illustrate our proposal keeps the promise of practicality, stability and efficiency.
Keywords :
IP networks; computer network security; packet switching; telecommunication network routing; IETF; SAVI promotion; SAVI switch access user motivation; SAVT; antispoofing device; campus network; destination-address-directed forwarding; filter router; network security breach events; source IP addresses; source address traceback; source address validation improvement; user local subnet; Filtering; IP networks; Proposals; Routing protocols; Switches; Topology;
Conference_Titel :
Computer Communications and Networks (ICCCN), 2011 Proceedings of 20th International Conference on
Conference_Location :
Maui, HI
Print_ISBN :
978-1-4577-0637-0
DOI :
10.1109/ICCCN.2011.6005783