EZ-SAVE: Evaluation of Easy-to-Deploy Source Address Validation Policies
Nicholas Scaglione, Justin Furuness, Yossi Gilad, Hemi Leibowitz, Cameron Morris, Bing Wang, Kotikalapudi Sriram, Amir Herzberg
摘要
The lack of Source Address Validation (SAV) is a significant vulnerability of the Internet, which is abused in many Denial-of-Service (DoS) and other attacks. Several IETF RFCs define easy-to-deploy, non-interactive SAV designs; the IETF is currently developing another SAV mechanism, BAR-SAV, which, as its name suggests, uses BGP, ASPA (Autonomous System Provider Authorization), and ROA (Route Origin Authorization) data. However, no comparative evaluation of the potential impact of their large-scale deployment has been done. A recent survey of network vendors and operators indicates that more efficacy data and usage guidelines are necessary to motivate their adoption.
We present EZ-SAVE, the first simulation-based analysis evaluating easy-to-deploy SAV policies. We measure both the spoofed traffic detection rates and the legitimate traffic filtering (false-positive) rates for each standard and proposed design at different adoption rates, using a realistic Internet topology and traffic engineering policies. Our results reveal several significant insights that may assist and guide the standardization process as well as developers and operators. In particular, we find that BAR-SAV proves to be the most effective design that features high spoof detection rates and low (or even zero) false-positive rates, motivating its standardization and deployment. Our results also provide operators with guidance on other SAV mechanisms that are effective for specific scenarios. In addition, our results highlight the importance of using realistic export policies for SAV evaluation.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它它引用的顶会 Paper8
- Are We There Yet? On RPKI's Deployment and SecurityYossi Gilad, Avichai Cohen, Amir Herzberg, Michael Schapira 等NDSS 2017 · 被引用 108 次
- Network Hygiene, Incentives, and Regulation: Deployment of Source Address Validation in the InternetMatthew J. Luckie, Robert Beverly, Ryan Koga, Ken Keys 等CCS 2019 · 被引用 89 次
- Deployment of Source Address Validation by Network Operators: A Randomized Control TrialQasim Lone, Alisa Frik, Matthew Luckie, Maciej Korczynski 等S&P 2022 · 被引用 16 次
- Suppressing BGP Zombies with Route Status TransparencyYosef Edery Anahory, Jie Kong, Nicholas Scaglione, Justin Furuness 等NSDI 2025 · 被引用 2 次
- ROV++: Improved Deployable Defense against BGP HijackingReynaldo Morillo, Justin Furuness, Cameron Morris, James Breslin 等NDSS 2021
相关 Paper
- Securing BGP ASAP: ASPA and other Post-ROV DefensesJustin Furuness, Cameron Morris, Reynaldo Morillo, Arvind Kasiliya 等NDSS 2025
- OSAVRoute: Advancing Outbound Source Address Validation Deployment Detection with Non-Cooperative MeasurementShuai Wang, Ruifeng Li, Li Chen, Dan Li 等NDSS 2026 · 被引用 3 次
- Aliens Among Us: Observing Private or Reserved IPs on the Public InternetRadu Anghel, Carlos Gañán, Qasim Lone, Matthew Luckie 等NDSS 2026
- ROV-MI: Large-Scale, Accurate and Efficient Measurement of ROV DeploymentWenqi Chen, Zhiliang Wang, Dongqi Han, Chenxin Duan 等NDSS 2022
- Your Router is My Prober: Measuring IPv6 Networks via ICMP Rate Limiting Side ChannelsLong Pan, Jiahai Yang, Lin He, Zhiliang Wang 等NDSS 2023
