华中科技大学学报(自然科学版)2016,Vol.44Issue(11):11-15,5.DOI:10.13245/j.hust.161103
基于自治域防御联盟源宣告的域间源地址验证
Inter-AS source address validation based on source declaration and AS alliance
摘要
Abstract
To solve the problem that when IETF (Internet engineering task force) SAVI (source ad‐dress validation improvement) working group focuses on solving the problem of source address valida‐tion in access network ,validation among AS (autonomous systems) still faces enormous challenges , based on Ingress/Egress Filtering technology ,a alliance system was proposed to upgrade the capabili‐ty in inter‐AS source validation .By designing the source declaration method and routing policies ,re‐lated configurations were put forwarded for each AS in alliance to enhance its filtering performance with lightweight costs .By exploring the phenomenon of multi‐path and declaration mistake ,the study of the policy in source declaration could not only avoids the potential false positive ,but also affirm the feasibility in inter‐AS source address validation for AS alliance based on filtering technologies .关键词
分布式拒绝服务攻击/IP源地址验证/自治域间/网络安全/源宣告Key words
distributed denial of service attack (DDoS)/IP source address validation/inter-AS/inter-net security/source declaration分类
信息技术与安全科学引用本文复制引用
贾溢豪,任罡,刘莹..基于自治域防御联盟源宣告的域间源地址验证[J].华中科技大学学报(自然科学版),2016,44(11):11-15,5.基金项目
国家自然科学基金资助项目(NSFC61402257);清华大学自主科研资助项目(2014z21051). ()