BGP Extension to Support Inter-Domain Distributed Packets Filtering
نویسندگان
چکیده
To be trustworthy is an important characteristic of the next generation Internet. The routing system of the present Internet forwards packets only according to the destination IP address. Forged packets with spoofed source IP address will also be forwarded to the destination, which impairs the security of receiver and conceals the real identity of the sender. The trustworthy Internet requires the routing system not only forward packets correctly, but also validate the packets from the real sender. Inter-domain distributed packet filtering is an effective method to filter out spoofed packets. This paper proposes to extend BGP with route selection notice to provide filtering criteria. With the support, border routers can validate incoming packets and filter the spoofed packets form false autonomous systems. Simulation result indicates BGP route selection notice does not impair the routing function of BGP, and both proper design acceptable bandwidth cost and fast convergence may be achieved simultaneously.
منابع مشابه
PERFORMANCE EVALUATION OF ROUTE-BASED DISTRIBUTED PACKET FILTERING FOR DDOS PREVENTION IN LARGE-SCALE NETWORKS A Thesis
Kim, HyoJeong. M.S., Purdue University, December, 2003. Performance Evaluation of Route-based Distributed Packet Filtering for DDoS Prevention in Large-scale Networks. Major Professor: Kihong Park. This thesis studies performance evaluation of route-based distributed packet filtering (DPF) for spoofed distributed denial of service (DDoS) attack prevention in large-scale networks under dynamic n...
متن کاملInter-Domain QoS Routing: Optimal and Practical Study
This paper addresses the problem of inter-domain QoS routing with Service Level Agreements (SLA) for data transport between peering domains, using virtual-trunk type aggregates. The problem is formally stated and formulated in Integer Linear Programming. As a practical solution, we define the QoS INFO extension to the BGP routing protocol, conveying three different QoS metrics (light load delay...
متن کاملRFC 5575 Flow
This document defines a new Border Gateway Protocol Network Layer Reachability Information (BGP NLRI) encoding format that can be used to distribute traffic flow specifications. This allows the routing system to propagate information regarding more specific components of the traffic aggregate defined by an IP destination prefix. Additionally, it defines two applications of that encoding format:...
متن کاملNetwork Working Group P. Marques Request for Comments: 5575 Cisco Systems Category: Standards Track Dissemination of Flow Specification Rules
This document defines a new Border Gateway Protocol Network Layer Reachability Information (BGP NLRI) encoding format that can be used to distribute traffic flow specifications. This allows the routing system to propagate information regarding more specific components of the traffic aggregate defined by an IP destination prefix. Additionally, it defines two applications of that encoding format:...
متن کاملIncentive Based Inter-domain Routing
The Internet’s inter-domain routeing system has evolved to keep pace with the Internet’s rapid growth, from a few co-operatively managed administrative domains to a large number of competetive domains. This growth has brought to light one of the Internet’s shortcomings: lack of support for efficient control and management of traffic, particularly between domains. This paper presents an extensio...
متن کامل