Abstract
Martian address filtering refers to a technique that discards IP packets that have an invalid source or destination address. This paper evaluates its effectiveness (or lack thereof) under denial of service (DoS) attack or host scan, in terms of packet-level and flow-level filtering performance. In order to overcome the shortcoming of Martian address filtering, we consider two extensions: unallocated address checking and blacklisting. We demonstrate through trace-based simulation that these techniques can indeed boost filtering performance. We also analyze the performance and the possible side-effects of the extensions.
Original language | English |
---|---|
Pages | 1348-1352 |
Number of pages | 5 |
State | Published - 2003 |
Event | IEEE Global Telecommunications Conference GLOBECOM'03 - San Francisco, CA, United States Duration: 1 Dec 2003 → 5 Dec 2003 |
Conference
Conference | IEEE Global Telecommunications Conference GLOBECOM'03 |
---|---|
Country/Territory | United States |
City | San Francisco, CA |
Period | 1/12/03 → 5/12/03 |
Keywords
- Denial-of-service attack
- Host scan
- Martian addresses
- Packet filtering
- Stateful inspection