Distributed Denial of Service (DDoS) attacks are one of the main threats facing the Internet today, and a considerable number of them originate from attacks using spoofed source addresses. The Source Address Verification Architecture (SAVA) technology can effectively mitigate such attacks by verifying the legitimacy of the source address. However, the deployment of SAVA faces some practical challenges, including the complexity of real network topologies, high deployment costs, and the impracticality of full deployment. To address these issues, this paper describes the SAVA deployment model in detail and proposes an incremental deployment approximation algorithm. The algorithm can identify a set of approximately optimal SAVA deployment points in any network topology, aiming to maximize the filtering of attack traffic. Experimental results show that compared with conventional deployment methods, the deployment algorithm shows superior performance in handling spoofed source attacks while maintaining a low false negative probability.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

SAVA Deployment for Spoofed Source Attacks

  • Wenjie Yang,
  • Yong Tang,
  • Wenyong Wang

摘要

Distributed Denial of Service (DDoS) attacks are one of the main threats facing the Internet today, and a considerable number of them originate from attacks using spoofed source addresses. The Source Address Verification Architecture (SAVA) technology can effectively mitigate such attacks by verifying the legitimacy of the source address. However, the deployment of SAVA faces some practical challenges, including the complexity of real network topologies, high deployment costs, and the impracticality of full deployment. To address these issues, this paper describes the SAVA deployment model in detail and proposes an incremental deployment approximation algorithm. The algorithm can identify a set of approximately optimal SAVA deployment points in any network topology, aiming to maximize the filtering of attack traffic. Experimental results show that compared with conventional deployment methods, the deployment algorithm shows superior performance in handling spoofed source attacks while maintaining a low false negative probability.