Telecommunications Science ›› 2020, Vol. 36 ›› Issue (10): 21-28.doi: 10.11959/j.issn.1000-0801.2020289

• Topic:Intelligent Communication Technology • Previous Articles     Next Articles

Internet source address verification method based on synchronization and dynamic filtering in address domain

Dan LI1,Lancheng QIN1,Jianping WU1,Yingying SU1,Mingwei XU1,Xingang SHI1,Yunan GU2,Tao LIN3   

  1. 1 Tsinghua University,Beijing 100084,China
    2 Huawei Technologies Co.,Ltd.,Beijing 100095,China
    3 New H3C Technologies Co.,Ltd.,Beijing 100102,China
  • Revised:2020-10-10 Online:2020-10-20 Published:2020-11-07
  • Supported by:
    The National Key Research and Development Program of China(2018YFB1800600);The National Natural Science Foundation of China(61772305);The Research and Development Program in Key Areas of Guangdong Province of China(2018B010113001)

Abstract:

At the beginning of the design of the Internet architecture,it assumed that all network members were trusted,and did not fully consider the security threat brought by the untrusted network members.For a long time,routers only forward packets based on the destination IP address of the packet,and do not carry out any verification on the source IP address of the packet.The lack of packet level authenticity on the Internet results in the header being maliciously altered.A real source address verification mechanism with routing synchronization and dynamic filtering were proposed.This mechanism constructs the filter table based on the prefix-topology mapping synchronization,the problem of inconsistent state between the filter table and the route caused by routing asymmetry were solved,false positives and false negatives was avoided,and a low-overhead and low-latency source address verification of the IP address prefix level granularity in the address domain were realized.

Key words: source address verification, IP source address forgery, routing synchronization, dynamic filtering

CLC Number: 

No Suggested Reading articles found!