论文部分内容阅读
拒绝服务攻击严重影响Internet的可用性,而攻击者通常采用源IP欺骗方式,使得网络防御更加困难.尽管已经提出许多防御IP欺骗的机制,但只是部分部署,防御效果差.本文首次提出一种域间IP欺骗防御服务扩展机制-MASK,在给定防御节点覆盖的情况下,延伸防御机制保护范围,增强节点的防御能力.借鉴Transit-Stub AS模型,根据BGP消息MASK节点代理邻居中Stub AS与目的端AS协商标识,共享源IP地址空间信息,向Stub AS提供IP欺骗防御服务.同时利用BGP消息约束源-目的端之间MASK会话数,减小了标识的计算和存储开销.MASK不仅扩大了防御机制保护范围,且提前过滤了IP欺骗数据流.应用Routeview提供的RIB进行评估,MASK在相同覆盖下能够扩展IP欺骗防御机制的保护范围,是一种高效的域间IP欺骗防御机制,可为建设新一代可信网络提供有力支撑.
Denial of service attacks seriously affect the availability of the Internet, and attackers usually use source IP spoofing, making network defense more difficult.Although many mechanisms have been proposed to defend against IP spoofing, but only partial deployment, the defense effect is poor.This paper proposes for the first time a domain Extended defense mechanism to extend the scope of protection mechanism and enhance the node’s defense ability.According to the Transit-Stub AS model, according to the BGP message MASK node proxy neighbor Stub AS and Destination AS negotiates the identity, shares the source IP address space information, and provides the IP spoofing defense service to the Stub AS. At the same time, BGP messages are used to reduce the number of MASK sessions between the source and the destination so as to reduce the computation and storage overhead of the identity. Defense of the scope of the protection mechanism, and pre-filter the IP spoofing data flow.Application Routeview RIB evaluation, MASK in the same coverage to extend the protection of IP spoofing defense mechanism is an efficient inter-domain IP spoofing defense mechanism, It can provide strong support for building a new generation of trusted networks.