Netinfo Security ›› 2019, Vol. 19 ›› Issue (5): 22-29.doi: 10.3969/j.issn.1671-1122.2019.05.003

Previous Articles     Next Articles

Intrusion Collaborative Disposal Method of Spoofed IP Address in DDoS Attacks

Ke ZHANG1(), Youjie WANG2, Shaoyin CHENG3, Lidong WANG4   

  1. 1. Anhui Branch, National Computer Network Emergency Response Technical Team, Hefei Anhui 230041, China
    2. Anhui Telecom Network Security Operation Center, Hefei Anhui 230031, China
    3. School of Cyber Security, University of Science and Technology of China, Hefei Anhui 230027, China
    4. Anhui Institute of Electronic Products Supervision and Inspection(Anhui Information Security Testing Evaluation Center),Hefei Anhui 230061, China
  • Received:2019-03-04 Online:2019-05-10 Published:2020-05-11

Abstract:

Spoofed IP address is the basis of many DDoS attacks, which makes it difficult to trace and respond to security incidents. URPF is mainly used to prevent the network attacks based on the source address spoofing. Network ingress filtering is used to check the packets from the network inside. On basis of telecom enterprise network this paper proposes the spoofed IP address collaborative disposal method based on the URPF technology and network ingress filtering, which realizes double filtering of the spoofed IP address inside the network and on the boundary export. Experiments show that this method can effectively prevent spoofed IP address traffic. After the large-scale application of Anhui telecom backbone network, monitoring data from CNCERT confirmed that Anhui telecom backbone routers have no local forged traffic and cross-domain forged traffic.

Key words: network security, DDoS attack, spoofed IP address, URPF, network ingress filtering

CLC Number: