• DocumentCode
    710426
  • Title

    An inter-AS path vector filter: towards elimination of false negatives

  • Author

    Zhou Zhang ; Ying Liuy ; Jianping Wuy ; Reny, Gang ; Jun Bi

  • Author_Institution
    Dept. of Comput. Sci. & Technol., Tsinghua Univ., Beijing, China
  • fYear
    2015
  • fDate
    22-24 April 2015
  • Firstpage
    1
  • Lastpage
    2
  • Abstract
    IP spoofing based attacks remains a serious and open security problem due to the fact that the current Internet implements no source address authentication mechanisms. A series of anti-spoofing practices have long been proposed while their actual implementation seems far from satisfactory. Route based filters were extensively studied in the design of Inter-AS source address validation methods. Traditional route based filters only use route direction information to establish filtering rules, causing inherited fake negatives. A novel inter-AS filter based on route path vector is proposed to reduce or even eliminate such fake negatives in this article. We name the filter IPVF (Inter-AS Path Vector Filter), which utilizes the route information of both path and distance, exhibits measurable increase in performance and incurs acceptable additional bandwidth cost. Moreover, traditional route based filtering rules is easy to be deduced by attackers. Since the filtering rules of IPVF could change over time by setting parameters, its actual improvement in performance could be exponentially increased.
  • Keywords
    IP networks; Internet; computer network security; telecommunication network routing; IP spoofing based attacks; IPVF filter; Internet; antispoofing practices; bandwidth cost; false negative elimination; interAS path vector filter; interAS source address validation methods; open security problem; route based filters; route direction information; source address authentication mechanisms; IP networks; Information filtering; Internet; Routing; Routing protocols; Security; Filtering; IP Source Address Validation; IP Spoofing;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Local and Metropolitan Area Networks (LANMAN), 2015 IEEE International Workshop on
  • Conference_Location
    Beijing
  • Type

    conf

  • DOI
    10.1109/LANMAN.2015.7114734
  • Filename
    7114734