An incrementally deployable path address scheme

被引:0
|
作者
Yoon, MyungKeun [2 ]
Chen, Shigang [1 ]
机构
[1] Univ Florida, Dept Comp Sci, Gainesville, FL 32611 USA
[2] Kookmin Univ, Dept Comp Engn, Seoul 136702, South Korea
基金
新加坡国家研究基金会; 美国国家科学基金会;
关键词
Internet protocols; Path address; Network security;
D O I
10.1016/j.jpdc.2012.05.001
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
The research community has proposed numerous network security solutions, each dealing with a specific problem such as address spoofing, denial-of-service attacks, denial-of-quality attacks, reflection attacks, viruses, or worms. However, due to the lack of fundamental support from the Internet, individual solutions often share little common ground in their design, which causes a practical problem: deploying all these vastly different solutions will add exceedingly high complexity to the Internet routers. In this paper, we propose a simple generic extension to the Internet, providing a new type of information, called path addresses, that simplify the design of security systems for packet filtering, fair resource allocation, packet classification, IP traceback, filter push-back, etc. IP addresses are owned by end hosts; path addresses are owned by the network core, which is beyond the reach of the hosts. We describe how to enhance the Internet protocols for path addresses that meet the uniqueness requirement, completeness requirement, safety requirement, and incrementally deployable requirement. We evaluate the performance of our scheme both analytically and by simulations, which show that, at small overhead, the false positive ratio and the false negative ratio can both be made negligibly small. (C) 2012 Elsevier Inc. All rights reserved.
引用
收藏
页码:1215 / 1225
页数:11
相关论文
共 50 条
  • [1] An Incrementally Deployable Network Traceback Scheme
    Tian, Hongcheng
    Wang, Hong
    Li, Li
    2018 IEEE 3RD INTERNATIONAL CONFERENCE ON CLOUD COMPUTING AND BIG DATA ANALYSIS (ICCCBDA), 2018, : 430 - 438
  • [2] Incrementally deployable IP traceback scheme based on sampled flows
    Tian, Hongcheng
    Bi, Jun
    Wang, Hong
    Qinghua Daxue Xuebao/Journal of Tsinghua University, 2014, 54 (11): : 1502 - 1510
  • [3] An Incrementally Deployable Flow-Based Scheme for IP Traceback
    Tian, Hongcheng
    Bi, Jun
    IEEE COMMUNICATIONS LETTERS, 2012, 16 (07) : 1140 - 1143
  • [4] Incrementally-Deployable Security for Interdomain Routing
    Rexford, Jennifer
    Feigenbaum, Joan
    CATCH 2009: CYBERSECURITY APPLICATIONS AND TECHNOLOGY CONFERENCE FOR HOMELAND SECURITY, PROCEEDINGS, 2009, : 130 - +
  • [5] Less Pain, Most of the Gain: Incrementally Deployable ICN
    Fayazbakhsh, Seyed Kaveh
    Lin, Yin
    Tootoonchian, Amin
    Ghodsi, Ali
    Koponen, Teemu
    Maggs, Bruce M.
    Ng, K. C.
    Sekar, Vyas
    Shenker, Scott
    ACM SIGCOMM COMPUTER COMMUNICATION REVIEW, 2013, 43 (04) : 147 - 158
  • [6] An incrementally deployable approach for achieving fair rate allocations
    Blanpain, Y
    Sivakumar, R
    COMPUTER NETWORKS-THE INTERNATIONAL JOURNAL OF COMPUTER AND TELECOMMUNICATIONS NETWORKING, 2002, 40 (04): : 499 - 513
  • [7] An incrementally deployable approach for achieving fair rate allocations
    Blanpain, Y
    Anantharaman, V
    Sivakumar, R
    TENTH INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATIONS AND NETWORKS, PROCEEDINGS, 2001, : 454 - 459
  • [8] Incrementally-deployable Indoor Navigation with Automatic Trace Generation
    Shu, Yuanchao
    Li, Zhuqi
    Karlsson, Borje
    Lin, Yiyong
    Moscibroda, Thomas
    Shin, Kang
    IEEE CONFERENCE ON COMPUTER COMMUNICATIONS (IEEE INFOCOM 2019), 2019, : 2395 - 2403
  • [9] An incrementally deployable energy efficient 802.15.4 MAC protocol (DEEP)
    Valero, Marco
    Jung, Sang Shin
    Bourgeois, Anu G.
    Beyah, Raheem
    AD HOC NETWORKS, 2012, 10 (07) : 1238 - 1252
  • [10] An incrementally deployable anti-spoofing mechanism for software-defined networks
    Kwon, Jonghoon
    Seo, Dongwon
    Kwon, Minjin
    Lee, Heejo
    Perrig, Adrian
    Kim, Hyogon
    COMPUTER COMMUNICATIONS, 2015, 64 : 1 - 20