Bootstrapping accountability in the internet we have

NSDI(2011)

引用 37|浏览23
暂无评分
摘要
Lack of accountability makes the Internet vulnerable to numerous attacks, including prefix hijacking, route forgery, source address spoofing, and DoS flooding attacks. This paper aims to bring accountability to the Internet with low-cost and deployable enhancements. We present IPA, a design that uses the readily available top-level DNSSEC infrastructure and BGP to bootstrap accountability. We show how IPA enables a suite of security modules that can combat various network-layer attacks. Our evaluation shows that IPA introduces modest overhead and is gradually deployable. We also discuss how the design incentivizes early adoption.
更多
查看译文
关键词
source address spoofing,early adoption,available top-level dnssec infrastructure,route forgery,numerous attack,security module,modest overhead,bootstrapping accountability,dos flooding attack,prefix hijacking,deployable enhancement
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要