CONSTRUCTING INTER-DOMAIN PACKET FILTERS TO CONTROL IP SPOOFING BASED ON BGP UPDATES-
#1

CONSTRUCTING INTER-DOMAIN PACKET FILTERS TO CONTROL IP SPOOFING BASED ON BGP UPDATES-- DEPENDABLE AND SECURE COMPUTING


Abstract: The Distributed Denial-of-Service (DDoS) attack is a serious threat to the legitimate use of the Internet. Prevention mechanisms are thwarted by the ability of attackers to forge or spoof the source addresses in IP packets. By employing IP spoofing, attackers can evade detection and put a substantial burden on the destination network for policing attack packets. In this paper, we propose an inter-domain packet filter (IDPF) architecture that can mitigate the level of IP spoofing on the Internet. A key feature of our scheme is that it does not require global routing information. IDPFs are constructed from the information implicit in Border Gateway Protocol (BGP) route updates and are deployed in network border routers. We establish the conditions under which the IDPF framework correctly works in that it does not discard packets with valid source addresses. Based on extensive simulation studies, we show that, even with partial deployment on the Internet, IDPFs can proactively limit the spoofing capability of attackers. In addition, they can help localize the origin of an attack packet to a small number of candidate networks.
Technology to use:JAVA
Reply
#2
[attachment=4514]
This article is presented by:
Zhenhai Duan, Xin Yuan
Department of Computer Science
Florida State University.

Jaideep Chandrashekar
Department of Computer Science
University of Minnesota



Constructing Inter-Domain Packet Filters to Control IP Spoofing Based on BGP Updates


Route based packet filtering [K. Park, SIGCOMM 2001]
One can fake the identity, but not the route.
A router can decide whether it is in the path from the source to the destination and drop packets that are not supposed to be there.
Route based packet filtering Requirement:
The router must know the route between any pair of source and destination addresses.
Global topology information
Not available in BGP.

Is it possible to build route based packet filters from BGP updates?
If it is possible, what is the performance?

BGP:
Autonomous Systems (ASes) are the basic units
The network can be modeled as an AS graph
Nodes are ASes and edges are BGP sessions
Nodes own network prefixes and exchange BGP route updates to learn the reachability of prefixes
Attributes associated with routes: AS path, prefix.

Policy based routing:
Import
Route selection
Export
BGP:
Routing policies are usually decided by the AS relation
Provider-customer
Peer-peer
Sibling-sibling



Reply
#3

to get information about the topic Constructing Inter-Domain Packet Filters to Control IP Spoofing Based on BGP Updates full report ppt and related topic refer the page link bellow

http://studentbank.in/report-constructin...ates--5836
Reply

Important Note..!

If you are not satisfied with above reply ,..Please

ASK HERE

So that we will collect data for you and will made reply to the request....OR try below "QUICK REPLY" box to add a reply to this page
Popular Searches: iris ip spoofing, free ieee paper filters, bgp multipath, constructing inter domain packet filters to control ip, which security model is used to constructing inter domain packet filters to control ip spoofing with bgp updates, ip spoofing ieee pdf, yale student updates,

[-]
Quick Reply
Message
Type your reply to this message here.

Image Verification
Please enter the text contained within the image into the text box below it. This process is used to prevent automated spam bots.
Image Verification
(case insensitive)

Possibly Related Threads...
Thread Author Replies Views Last Post
  Service-Oriented Architecture for Weaponry and Battle Command and Control Systems in 1 1,064 15-02-2017, 03:40 PM
Last Post: jaseela123d
  Packet-Hiding Methods for Preventing Selective Jamming Attacks 1 680 14-02-2017, 11:35 AM
Last Post: ijasti
  ATM access control using fingerprint scanning smart paper boy 8 5,729 01-07-2016, 11:42 AM
Last Post: jaseela123d
  Adaptive Forwarding Delay Control for VANET Data Aggregation Projects9 2 1,731 18-03-2014, 11:25 PM
Last Post: seminar report asees
  RATIONSHOP INVENTORY CONTROL SYSTEM full report smart paper boy 5 5,747 04-10-2013, 05:33 AM
Last Post: harish pr
  Packet-Hiding Methods for Preventing Selective Jamming Attacks Projects9 5 4,374 30-07-2013, 05:30 PM
Last Post: mounikabujji
  Intelligent system for Gas, Human detection and Temperature Monitor control using GSM seminar surveyer 3 3,478 17-04-2013, 11:37 PM
Last Post: [email protected]
  Achieving Secure, Scalable, and Fine-grained Data Access Control in Cloud Computing seminar class 1 1,968 29-10-2012, 05:31 PM
Last Post: seminar details
  Design and Analysis of the Gateway Relocation and Admission Control Algorithm in Mobi Projects9 1 1,721 10-10-2012, 12:22 PM
Last Post: seminar details
  A Geometric Approach to Improving Active Packet Loss Measurement full report project topics 2 2,630 09-04-2012, 06:01 PM
Last Post: [email protected]

Forum Jump: