A simple packet authentication mechanism based on stateless core approach
Shuai Hao, Huang Xiaohong, Yan Ma · 2010
The addressing and forwarding architecture based on the destination of packets in current Internet typically does not check the authenticity of source address of packets; therefore, it causes a considerable challenge to prevent the attackers from launching attacks by forging source addresses and to trace the real sources which sent the malicious traffic. In this paper, we present a new protocol/architecture designed to enhance network security by separately verifying the authenticity of source address in the ingress of access network and the credibility of packet path on the border of every domain. The access validation bases on the label generated by host; the packet authentication is implemented by an indicator of accumulated information of domains which the packets pass through. This mechanism intrinsically provides the IP traceback. This paper also discusses the issues of development and deployment in practice, and two prototype drafts are given.