{"title":"一种有效的IP欺骗报文检测与过滤方法","authors":"T. Ohtsuka, F. Nakamura, Y. Sekiya, Y. Wakahara","doi":"10.1109/ICICT.2007.375404","DOIUrl":null,"url":null,"abstract":"In the Internet there are a lot of distributed denial of service (DDoS) attacks. A lot of attacks aim to cause damage to services such as web, ire and DNS. However, there is no efficient method to protect regular traffic from the attacks. In this paper we propose FSN method to detect and filter out the attacks efficiently as much as possible, near the attackers. FSN method is effective and practical and applicable to the real Internet environment. FSN method uses topology information to detect the attacks and collects topology information using IGP routing protocol, so it is applicable to the environments including asymmetric paths and it doesn't require collected packets to construct neighbor information. To evaluate FSN method we perform some simulations compared to reverse path forwarding (RPF). The simulation results show FSN method can prevent the attacks more efficiently than RPF and filter out the attacks in the environments including asymmetric paths. According to the results, we conclude FSN method is very effective and practical.","PeriodicalId":206443,"journal":{"name":"2007 International Conference on Information and Communication Technology","volume":"46 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2007-03-07","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"6","resultStr":"{\"title\":\"Proposaland Efficient Implementation of Detecting and Filtering Method for IP Spoofed Packets\",\"authors\":\"T. Ohtsuka, F. Nakamura, Y. Sekiya, Y. Wakahara\",\"doi\":\"10.1109/ICICT.2007.375404\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"In the Internet there are a lot of distributed denial of service (DDoS) attacks. A lot of attacks aim to cause damage to services such as web, ire and DNS. However, there is no efficient method to protect regular traffic from the attacks. In this paper we propose FSN method to detect and filter out the attacks efficiently as much as possible, near the attackers. FSN method is effective and practical and applicable to the real Internet environment. FSN method uses topology information to detect the attacks and collects topology information using IGP routing protocol, so it is applicable to the environments including asymmetric paths and it doesn't require collected packets to construct neighbor information. To evaluate FSN method we perform some simulations compared to reverse path forwarding (RPF). The simulation results show FSN method can prevent the attacks more efficiently than RPF and filter out the attacks in the environments including asymmetric paths. According to the results, we conclude FSN method is very effective and practical.\",\"PeriodicalId\":206443,\"journal\":{\"name\":\"2007 International Conference on Information and Communication Technology\",\"volume\":\"46 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2007-03-07\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"6\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2007 International Conference on Information and Communication Technology\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/ICICT.2007.375404\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2007 International Conference on Information and Communication Technology","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICICT.2007.375404","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
Proposaland Efficient Implementation of Detecting and Filtering Method for IP Spoofed Packets
In the Internet there are a lot of distributed denial of service (DDoS) attacks. A lot of attacks aim to cause damage to services such as web, ire and DNS. However, there is no efficient method to protect regular traffic from the attacks. In this paper we propose FSN method to detect and filter out the attacks efficiently as much as possible, near the attackers. FSN method is effective and practical and applicable to the real Internet environment. FSN method uses topology information to detect the attacks and collects topology information using IGP routing protocol, so it is applicable to the environments including asymmetric paths and it doesn't require collected packets to construct neighbor information. To evaluate FSN method we perform some simulations compared to reverse path forwarding (RPF). The simulation results show FSN method can prevent the attacks more efficiently than RPF and filter out the attacks in the environments including asymmetric paths. According to the results, we conclude FSN method is very effective and practical.