ingress filtering to stop source address spoofing
Posted Apr 23, 2004 21:28 UTC (Fri) by
giraffedata (subscriber, #1954)
In reply to:
TCP vulnerability: cancel red alert by pflugstad
Parent article:
TCP vulnerability: cancel red alert
This doesn't work except at the very edge of the network.
Doing it at the edge would probably be sufficient.
In fact, I thought it already was already done there. Can an AOL or Earthlink or Road Runner home Internet user send packets with arbitrary source IP addresses into the Internet? Have we had Internet hacks recently using spoofed IP source addresses?
It doesn't have to be the very edge, does it? Just beyond the point where the Internet becomes a tree. I assume most of the Internet nodes are in that outer region.
(
Log in to post comments)