AI Chat Paper
Note: Please note that the following content is generated by AMiner AI. SciOpen does not take any responsibility related to this content.
{{lang === 'zh_CN' ? '文章概述' : 'Summary'}}
{{lang === 'en_US' ? '中' : 'Eng'}}
Chat more with AI
PDF (3.2 MB)
Collect
Submit Manuscript AI Chat Paper
Show Outline
Outline
Show full outline
Hide outline
Outline
Show full outline
Hide outline

Preventing IP Source Address Spoofing: A Two-Level, State Machine-Based Method

Jun BI( )Bingyang LIUJianping WUYan SHEN
Tsinghua National Laboratory for Information Science and Technology, Network Research Center, Tsinghua University, China Education and Research Network (CERNET), Beijing 100084, China
Show Author Information

Abstract

A signature-and-verification-based method, automatic peer-to-peer anti-spoofing (APPA), is proposed to prevent IP source address spoofing. In this method, signatures are tagged into the packets at the source peer, and verified and removed at the verification peer where packets with incorrect signatures are filtered. A unique state machine, which is used to generate signatures, is associated with each ordered pair of APPA peers. As the state machine automatically transits, the signature changes accordingly. KISS random number generator is used as the signature generating algorithm, which makes the state machine very small and fast and requires very low management costs. APPA has an intra-AS (autonomous system) level and an inter-AS level. In the intra-AS level, signatures are tagged into each departing packet at the host and verified at the gateway to achieve finer-grained anti-spoofing than ingress filtering. In the inter-AS level, signatures are tagged at the source AS border router and verified at the destination AS border router to achieve prefix-level anti-spoofing, and the automatic state machine enables the peers to change signatures without negotiation which makes APPA attack-resilient compared with the spoofing prevention method. The results show that the two levels are both incentive for deployment, and they make APPA an integrated anti-spoofing solution.

References

【1】
【1】
 
 
Tsinghua Science and Technology
Pages 413-422

{{item.num}}

Comments on this article

Go to comment

< Back to all reports

Review Status: {{reviewData.commendedNum}} Commended , {{reviewData.revisionRequiredNum}} Revision Required , {{reviewData.notCommendedNum}} Not Commended Under Peer Review

Review Comment

Close
Close
Cite this article:
BI J, LIU B, WU J, et al. Preventing IP Source Address Spoofing: A Two-Level, State Machine-Based Method. Tsinghua Science and Technology, 2009, 14(4): 413-422. https://doi.org/10.1016/S1007-0214(09)70097-5

7

Views

0

Downloads

0

Crossref

0

Web of Science

0

Scopus

0

CSCD

Received: 01 March 2008
Revised: 19 February 2009
Published: 03 June 2026
© Tsinghua University Press 2009