CONSTRUCTING INTER-DOMAIN PACKET FILTERS TO CONTROL IP SPOOFING BASED ON BGP UPDATES-
#1

CONSTRUCTING INTER-DOMAIN PACKET FILTERS TO CONTROL IP SPOOFING BASED ON BGP UPDATES-- DEPENDABLE AND SECURE COMPUTING


Abstract: The Distributed Denial-of-Service (DDoS) attack is a serious threat to the legitimate use of the Internet. Prevention mechanisms are thwarted by the ability of attackers to forge or spoof the source addresses in IP packets. By employing IP spoofing, attackers can evade detection and put a substantial burden on the destination network for policing attack packets. In this paper, we propose an inter-domain packet filter (IDPF) architecture that can mitigate the level of IP spoofing on the Internet. A key feature of our scheme is that it does not require global routing information. IDPFs are constructed from the information implicit in Border Gateway Protocol (BGP) route updates and are deployed in network border routers. We establish the conditions under which the IDPF framework correctly works in that it does not discard packets with valid source addresses. Based on extensive simulation studies, we show that, even with partial deployment on the Internet, IDPFs can proactively limit the spoofing capability of attackers. In addition, they can help localize the origin of an attack packet to a small number of candidate networks.
Technology to use:JAVA
Reply
#2
[attachment=4514]
This article is presented by:
Zhenhai Duan, Xin Yuan
Department of Computer Science
Florida State University.

Jaideep Chandrashekar
Department of Computer Science
University of Minnesota



Constructing Inter-Domain Packet Filters to Control IP Spoofing Based on BGP Updates


Route based packet filtering [K. Park, SIGCOMM 2001]
One can fake the identity, but not the route.
A router can decide whether it is in the path from the source to the destination and drop packets that are not supposed to be there.
Route based packet filtering Requirement:
The router must know the route between any pair of source and destination addresses.
Global topology information
Not available in BGP.

Is it possible to build route based packet filters from BGP updates?
If it is possible, what is the performance?

BGP:
Autonomous Systems (ASes) are the basic units
The network can be modeled as an AS graph
Nodes are ASes and edges are BGP sessions
Nodes own network prefixes and exchange BGP route updates to learn the reachability of prefixes
Attributes associated with routes: AS path, prefix.

Policy based routing:
Import
Route selection
Export
BGP:
Routing policies are usually decided by the AS relation
Provider-customer
Peer-peer
Sibling-sibling



Reply
#3
to get information about the topic Constructing Inter-Domain Packet Filters to Control IP Spoofing Based on BGP Updates full report ppt and related topic refer the page link bellow

http://studentbank.in/report-constructin...ates--5836
Reply

Important Note..!

If you are not satisfied with above reply ,..Please

ASK HERE

So that we will collect data for you and will made reply to the request....OR try below "QUICK REPLY" box to add a reply to this page
Popular Searches: ip spoofing architecture, controlling ip spoofing through inter domain packet filters free download, what is spoofing, abstract control spoofing 2011, disadvantages of ip spoofing, ip spoofing fire, system design documentation for fuzzy self constructing,

[-]
Quick Reply
Message
Type your reply to this message here.

Image Verification
Please enter the text contained within the image into the text box below it. This process is used to prevent automated spam bots.
Image Verification
(case insensitive)

Possibly Related Threads...
Thread Author Replies Views Last Post
  Service-Oriented Architecture for Weaponry and Battle Command and Control Systems in 1 1,057 15-02-2017, 03:40 PM
Last Post: jaseela123d
  Packet-Hiding Methods for Preventing Selective Jamming Attacks 1 675 14-02-2017, 11:35 AM
Last Post: ijasti
  ATM access control using fingerprint scanning smart paper boy 8 5,721 01-07-2016, 11:42 AM
Last Post: jaseela123d
  Adaptive Forwarding Delay Control for VANET Data Aggregation Projects9 2 1,727 18-03-2014, 11:25 PM
Last Post: seminar report asees
  RATIONSHOP INVENTORY CONTROL SYSTEM full report smart paper boy 5 5,740 04-10-2013, 05:33 AM
Last Post: harish pr
  Packet-Hiding Methods for Preventing Selective Jamming Attacks Projects9 5 4,359 30-07-2013, 05:30 PM
Last Post: mounikabujji
  Intelligent system for Gas, Human detection and Temperature Monitor control using GSM seminar surveyer 3 3,466 17-04-2013, 11:37 PM
Last Post: [email protected]
  Achieving Secure, Scalable, and Fine-grained Data Access Control in Cloud Computing seminar class 1 1,960 29-10-2012, 05:31 PM
Last Post: seminar details
  Design and Analysis of the Gateway Relocation and Admission Control Algorithm in Mobi Projects9 1 1,721 10-10-2012, 12:22 PM
Last Post: seminar details
  A Geometric Approach to Improving Active Packet Loss Measurement full report project topics 2 2,628 09-04-2012, 06:01 PM
Last Post: [email protected]

Forum Jump: