SANALDA: A Source Authenticating Network Architecture Limiting DoS Attacks
Michael Sirivianos, Ersin Uzun, Ines Viskic · 2006
We present a novel and incrementally deployable network architecture, aiming at preventing IP spoofing and DoS attacks. Our design prevents forged IP packets from entering the network and accessing the destination service, while assuring simple and fast access to compliant users. Our system enforces user authentication on the IP level, periodically stamping each IP packet with a unique, identity-based signature of the sender. Spoofed packets are detected as soon as they arrive at the source authenticating router, by detecting discrepancies between signatures in the packet headers and their declared IP address or by checking special markings. In addition, we use capabilities to enable the receivers to decide which senders are allowed to send traffic. Hence, our architecture limits the impact of DoS attacks, which use either spoofed or non-spoofed IP traffic. To the best of our knowledge, no prior work has used Identity Based Signatures for IP host authen-tication. We propose an IBS-based solution that addresses a broad range of network vulnerabilities. We implemented our design as a router module to measure the associated performance degradation and demonstrate its potential for Internet-wide deployment.