In today's Internet routing architecture, the router doesn't validate the correctness of the source address carried in the packet, nor keep the state information when forwarding the packet. Thus the DDoS attacks with spoofed IP source address can cause security problems. In this paper, we aim to prevent the attackers from attacking somewhere outside the IPv6 edge network with forged source address in the fine granularity. The proposed methods include source address authentication by using session key and hash digest algorithm, and replay attack prevention by combining the sequence number method and the timestamp method. This paper presents the algorithm design and evaluates its feasibility and correctness by simulation experiments. © Springer-Verlag Berlin Heidelberg 2007.
CITATION STYLE
Xie, L., Bi, J., & Wu, J. (2007). An authentication based source address spoofing prevention method deployed in IPv6 edge network. In Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) (Vol. 4490 LNCS, pp. 801–808). Springer Verlag. https://doi.org/10.1007/978-3-540-72590-9_121
Mendeley helps you to discover research relevant for your work.