Application of SAVNET in typical ISP network scenarios
Xuejing Yuan, Jiaqi Sun, Zhihua Liu, Junya Huang · 2024
The next-generation Internet plays a significant role in carrying 5G, cloud computing, the Internet of Things, and other important technologies. It serves as a crucial network infrastructure for the development of digital China. However, during the initial design of the Internet, the security threats posed by untrustworthy activities were not adequately considered. Next-generation Internet equipment only forwards messages based on the IPv6 destination address, and this leaves the system vulnerable to attacks that involve forging the source address. Attackers use this method to impersonate the victim and launch distributed denial of service (DDoS) attacks. This type of attack is particularly damaging as it is cost-effective, difficult to trace, does not require a large number of "zombie hosts," and is highly aggressive, making it challenging to defend against. This poses significant harm to the next-generation Internet. SAVNET (Source Address Validation in Intra Domain Networks and Inter-domain Networks) offers an effective solution to the problem of Internet source address forgery. This technology employs a hierarchical trust federation and encryption label mechanism to efficiently verify source addresses, thus enhancing the security and credibility of the network. The paper introduces the application of SAVNET in typical scenarios of Internet Service Provider (ISP) networks, along with related source address verification technology. It also analyzes the technical principles, implementation methods, and challenges associated with this technology.