摘要
由于现今的网络缺乏源地址验证机制,导致多种依靠IP欺骗的恶意攻击时有发生。在DHCPv6场景中防止IP欺骗的源地址验证改进(SAVI)工作,目前正由互联网工程任务组(IETF)驱动,但尚未给出确切的源地址验证方法。为此,提出两个验证方法:改进的多比特Trie树算法和改进的哈希查找算法,实现了SAVI DHCPv6的仿真系统,并使用该系统进行不同验证方法的对比实验。结果表明,提出的两种改进方法比顺序查找方法具有更优的时间性能。
Current Intemet was lack of source address validation mechanism, resuhed in a variety of malicious attacks relying on IP spoofing. Source address validation improvements in DI4CPv6 scenario was an in-progress mechanism against IP spoofing driven by Internet Engineering Task Force, but still lack of data packet source address validation solutions. This paper proposed two solutions: improved multi-bits Trie algorithm and improved hash lookup algorithm. Then it implemented a SAVI DHCPv6 simulation system to test their performance. The result shows that the two improved solutions in this paper have better time performance than sequential lookup method.
出处
《计算机应用研究》
CSCD
北大核心
2017年第1期166-169,共4页
Application Research of Computers
基金
国家自然科学基金面上项目(61375039)
中科院网络中心一三五重点项目(CNIC_PY_1402)