Evasive Internet: Reducing Internet Vulnerability through Transient Addressing

Michael Rabinovich, Oliver Spatscheck · 2010

This paper presents our vision for Evasive Internet, where destinations are only reachable through capabilities, which serve as hosts' flat transient addresses. Just as today's host addresses, our capabilities are obtained from the DNS hierarchy, thus never exposing destinations themselves to unprotected traffic. Our design supports in-network authentication of transient addresses and attribution of traffic they generate; our design further gives hosts full control over incoming flows. We achieve these objectives without exposing hosts to unprotected capability request traffic and without distributed filtering infrastructure. While significant work is needed to flesh out our vision, we hope it will contribute to improving security in future networks.

Read the paper · More papers on PaperTik