Dissertation > Excellent graduate degree dissertation topics show

Source Address Validation Architecture Based on Stateless Core Approach

Author: HaoShuai
Tutor: MaYan
School: Beijing University of Posts and Telecommunications
Course: Computer Science and Technology
Keywords: Source Address Validation Domain-path Verifying Stateless Core Flow label
CLC: TP393.02
Type: Master's thesis
Year: 2010
Downloads: 48
Quote: 0
Read: Download Dissertation

Abstract


The addressing and forwarding architecture based on destination of packets in current Internet typically does not check the authenticity of packets’source addresses; therefore, it causes a considerable challenge in security to prevent the attackers from launching attacks by forging source addresses and trace the real sources which sent the malicious traffic. The source address validation technology has been considered as an essential component for the design and development of next generation Internet architecture.Enforcing the source address validation would help us achieve the goals:(1) since packets which carry spoofed source addresses would not be forwarded, it would be impossible to launch network attacks by using spoofed source addresses; (2) the authenticated source addresses would benefit network diagnosis, management, accounting, and applications. In this paper, a new protocol/architecture design is described to enhance network security by separately verifying the authenticity of source IP addresses in the ingress of access network and the credibility of packet path on the border of every domain. The access validation bases on the label generated by host; the path verification is implemented by an indicator of accumulated information of domains which the packets pass through, and this mechanism intrinsically provides the capability of tracing the attacker who sends the malicious packets. This architecture greatly reduces the network complexity and system overhead which is introduced by the source address validation. In addition, in the design and implementation of prototype, we presents a simplified model based on IPv6 Flow Label field which is used to carry the host-generated random tags to enhance the existing address binding mechanism in the access network and bear the path validation information in autonomous domain boundary by developing the BGP protocol extension. The prototype design based on PATH-ATTRIBUTE of BGP UPDATE message facilitates the development and deployment of source address validation architecture.

Related Dissertations

  1. Intranet IPv6 Transition Network Integration Platform,TP393.04
  2. Research on the Technology of Intra-domain Source Address Validation,TP393.08
  3. Switch-based Source Address Validation for IPv6,TP393.04
  4. Next Generation Internet packet identification and searching technology research,TN915.09
  5. Based on the IPv6 environment, network security testing Phishing defense research,TN915.08
  6. Mobile IPv6 environment of security services,TP393.08
  7. Research on the Congestion Control Algorithm in IPv6 Network,TP393.07
  8. Research of Overlay Routing Technology Based on Quality of Service,TP393.01
  9. The bandwidth control applied research in the grid environment,TP393.07
  10. Research and Implementation of IPv6 Flow Label in Multicast Management System,TN915.07
  11. IPv6 multimedia conferencing systems communication technology research,TN948.63
  12. The Application of Flow Label on Quality of Service over Heterogeneous Networks,TN915.07
  13. Research and Implementation of Flow Label in the QoS of Evolved Packet System,TN929.5
  14. Flow Label’s Application in Quality of Service and Its Generating Mechanism,TN915.07
  15. The Design and Realization of Packet Classification Based on Flow Label in IPv6,TP393.04
  16. Research on IPv6 Packet Classification Algorithm Based on Flow Label,TP393.04
  17. Research of QoS Based on IPv6 Flow Label,TP393.09
  18. The Research of Multicast System Based on IPv6,TP393.04
  19. Research on Peer-to-Peer Traffic Identification Algorithm Based on Cluster Analysis,TP393.02
  20. Research of Communication Mechanism in the Distributed Network Based on Mobile Agent,TP393.02
  21. IGMP packet Internet IP-level topology measurement method study,TP393.02

CLC: > Industrial Technology > Automation technology,computer technology > Computing technology,computer technology > Computer applications > Computer network > General issues > Computer network architecture and design
© 2012 www.DissertationTopic.Net  Mobile