Toward Practical Inter-Domain Source Address Validation


연구 분야: Verification



학회: IEEE/ACM Transactions on Networking, Volume 32, Issue 4


초록

The Internet Protocol (IP) is the most fundamental building block of the Internet. However, it provides no explicit notion of packet-level authenticity. Such a weakness allows malicious actors to spoof IP packet headers and launch a wide variety of attacks. Meanwhile, the highly decentralized management of Internet infrastructure makes large-scale source address validation challenging in terms of overhead, validity, and flexibility. This paper presents a practical anti-spoofing approach, Source Address Validation Architecture eXternal (SAVA-X). SAVA-X introduces the concept of Address Domain to enable address validation in finer, prefix-level granularity. The address domains are organized in nested hierarchies to provide higher scalability and lower maintenance costs for partial deployment. We implement SAVA-X on commercial backbone routers and the P4 platform. The experiments indicate that the hardware implementation of SAVA-X can achieve 98% throughput on 100 Gbps links and close to the native IP forwarding in per-packet overhead, with less than 10 microseconds additional processing latency.


Author Profile
Xiaoliang Wang

Information Engineering College Capital Normal University Beijing China

China
Author Profile
Ke Xu

Department of Computer Science and Technology Tsinghua University Beijing China

Andorra
Author Profile
Yangfei Guo

Zhongguancun Laboratory Beijing China

China

📄 논문 정보

발행 연도 2024년
인용수 0
출판 국가 Andorra, China, Mongolia
사이트 ACM
좋아요 수 0

연관 논문 목록 (97건)