An incrementally deployable path address scheme

被引:0
|
作者
Yoon, MyungKeun [2 ]
Chen, Shigang [1 ]
机构
[1] Univ Florida, Dept Comp Sci, Gainesville, FL 32611 USA
[2] Kookmin Univ, Dept Comp Engn, Seoul 136702, South Korea
基金
新加坡国家研究基金会; 美国国家科学基金会;
关键词
Internet protocols; Path address; Network security;
D O I
10.1016/j.jpdc.2012.05.001
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
The research community has proposed numerous network security solutions, each dealing with a specific problem such as address spoofing, denial-of-service attacks, denial-of-quality attacks, reflection attacks, viruses, or worms. However, due to the lack of fundamental support from the Internet, individual solutions often share little common ground in their design, which causes a practical problem: deploying all these vastly different solutions will add exceedingly high complexity to the Internet routers. In this paper, we propose a simple generic extension to the Internet, providing a new type of information, called path addresses, that simplify the design of security systems for packet filtering, fair resource allocation, packet classification, IP traceback, filter push-back, etc. IP addresses are owned by end hosts; path addresses are owned by the network core, which is beyond the reach of the hosts. We describe how to enhance the Internet protocols for path addresses that meet the uniqueness requirement, completeness requirement, safety requirement, and incrementally deployable requirement. We evaluate the performance of our scheme both analytically and by simulations, which show that, at small overhead, the false positive ratio and the false negative ratio can both be made negligibly small. (C) 2012 Elsevier Inc. All rights reserved.
引用
收藏
页码:1215 / 1225
页数:11
相关论文
共 50 条
  • [31] The Effectiveness of Passport Source Address Validation Scheme
    Lu, Ning-ning
    Zhou, Hua-chun
    Zhang, Hong-ke
    2009 ASIA-PACIFIC CONFERENCE ON INFORMATION PROCESSING (APCIP 2009), VOL 2, PROCEEDINGS, 2009, : 92 - 95
  • [32] THE ADDRESS BOOK Our place in the scheme of things
    Morris, Catharine
    TLS-THE TIMES LITERARY SUPPLEMENT, 2011, (5646): : 26 - 27
  • [33] Fast address generation scheme for FFT processor
    Department of Electronic Engineering, School of Information Science and Technology, Beijing Institute of Technology, Beijing 100081, China
    Beijing Ligong Daxue Xuebao, 2006, 1 (68-71):
  • [34] A fast and updatable IP address lookup scheme
    Chung, SH
    Jean, S
    Yoon, H
    Cho, JW
    2001 INTERNATIONAL CONFERENCE ON COMPUTER NETWORKS AND MOBILE COMPUTING, PROCEEDINGS, 2001, : 419 - 424
  • [35] A scheme for implementing address translation storage buffers
    Mohamed, AH
    Sagahyroon, A
    IEEE CCEC 2002: CANADIAN CONFERENCE ON ELECTRCIAL AND COMPUTER ENGINEERING, VOLS 1-3, CONFERENCE PROCEEDINGS, 2002, : 626 - 633
  • [36] A TCAM Index Scheme for IP Address Lookup
    Tang, Yi
    Lin, Wei
    Liu, Bin
    2006 FIRST INTERNATIONAL CONFERENCE ON COMMUNICATIONS AND NETWORKING IN CHINA, 2006,
  • [37] A Virtual MAC Address Scheme for Mobile Ethernet
    Yoshia Saito
    Masahiro Kuroda
    Tadanori Mizuno
    Wireless Personal Communications, 2005, 35 : 99 - 109
  • [38] Research on Displacement Mode and Path Tracking Method of Square Combined Deployable Mechanism
    Li J.
    Wang S.
    Peng Q.
    Li F.
    Xibei Gongye Daxue Xuebao/Journal of Northwestern Polytechnical University, 2019, 37 (06): : 1200 - 1208
  • [39] A large deployable antenna with tension Truss scheme and its electrical performances.
    Takano, T
    Natori, M
    Miyoshi, K
    Noguchi, T
    IEEE ANTENNAS AND PROPAGATION SOCIETY INTERNATIONAL SYMPOSIUM - ANTENNAS: GATEWAYS TO THE GLOBAL NETWORK, VOLS 1-4, 1998, : 2086 - 2089
  • [40] Control scheme for cable-mesh reflector adjustment on cablenet deployable antenna
    School of Mechatronics Engineering, Xidian University, Xi'an 710071, China
    Yingyong Lixue Xuebao, 2008, 1 (154-157):