Dissertation > Excellent graduate degree dissertation topics show
Research on the Technology of Intra-domain Source Address Validation
Author: CaiGuiLin
Tutor: WangBaoSheng
School: National University of Defense Science and Technology
Course: Computer Science and Technology
Keywords: Autonomous system Source address validation SVA
CLC: TP393.08
Type: Master's thesis
Year: 2010
Downloads: 26
Quote: 0
Read: Download Dissertation
Abstract
|
Based on source address spoofing attacks has become a major threat to network security . Source address validation techniques to solve the problem of source address spoofing effective method , has important theoretical significance and practical value. Currently, many researchers have proposed a variety of source address validation techniques . In this paper, these typical techniques to classify , summarize the main ideas of these technologies and the advantages and disadvantages , and on this basis propose a new source address validation architecture SVA (Source Validation Architecture). SVA provides two optional authentication mechanisms : active path identification mechanism Active SPi and OSPF auxiliary reverse path forwarding mechanism OAuRPF. Active SPi mechanism is the source address end system verification techniques by routers to mark packets , end systems perform filtering. The mechanism of an IP address to calculate the hash value tag value , using fixed length labeling scheme and the packet transmission path ahead will hop up and down the information tag to the packet . End system to take a proactive verification techniques , through the packet source sends authentication packets , response packets based on source identification value brought to determine the authenticity of the source address of the packet . The mechanism used to deploy the client system excitation filtering mechanism is relatively high, and can dynamically adapt to changes in network topology . Through the OSPF routing symmetry analysis , we propose a OAuRPF mechanism . OAuRPF belongs to the network source address validation techniques learned by the router based on the routing information to perform the filtering function. Need to add a route to the router control plane symmetry judgment module , based on an judgment on the current routing symmetry generates the appropriate filter rules , forming a matching table , and in the forwarding plane to add a source address validation module, and forwarding matching table and interact dynamically for packet filtering. This mechanism can improve uRPF mechanism in the case of asymmetric routing effectiveness and reduce legal asymmetric routing packet discard rate . This realization of the Linux-based systems, the source address validation architecture SVA prototype system , and build a variety of network topologies domain simulation test . The results showed that , SVA able to respond quickly to the source address of forgery attack , and the filtering effect is better.
|
Related Dissertations
- SystemVerilog-based functional verification module URAT,TN402
- Intranet IPv6 Transition Network Integration Platform,TP393.04
- The Research of Diversification Strategy of Radio and TV Group Based on the Core Competence,G221
- Source Address Validation Architecture Based on Stateless Core Approach,TP393.02
- Switch-based Source Address Validation for IPv6,TP393.04
- Research on Radio & TV Conglomeration Management,G229.23
- Xiamen Haitian Container Co., Ltd. SVA system planning and implementation of research,TP399
- Study on Synchronization Control of Chaotic and Fractional-order Chaotic Systems with Circuitry Experimental Verification,O415.5
- Techniques of Unauthorized Target Computer Network Topology Discovery,TP393.02
- MIMO radar signal detection and accumulation of long technical research,TN958
- Research and Implementation of Network Topology Discovery,TP393.02
- Research on Probabilistic Packet Marking Based on DoS Trace Route,TP393.08
- The villager autonomy context Village cadres role Exploration,D422.6
- Design and Verification of FPGA-based Network Protocol Processor,TN791
- The Research of System Verilog Assertion-Based Verification Method for Nand Flash Controller,TN402
- IPv4 IPv6 Coexistence Network Topology Discovery,TP393.02
- Several types of dynamical properties of Epidemic Model,O175
- Sva-laksana and Pratyaksa-pramana,B949
- Research on the Dynamic Behavior of Delayed Neural Networks with External Stimuli and Inertial Terms,TP183
- Some Mathematical Models of Infectious Diseases and Their Analysis,O242.1
CLC: > Industrial Technology > Automation technology,computer technology > Computing technology,computer technology > Computer applications > Computer network > General issues > Computer Network Security
© 2012 www.DissertationTopic.Net Mobile
|