A Practical SDN-based IP Spoofing Defense Method
Download: Paper (PDF)
Date: 27 Jul 2015
Document Type: Briefing Papers
Associated Event: NDSS Symposium 2015
IP spoofing has become one of major threats to the Internet, while popular defense methods like ingress/egress filtering cannot stop IP spoofing effectively. This poster introduces SIPD, a feasible and scalable SDN-based IP spoofing defense method, which runs on the SDN controller and is compatible with the OpenFlow specification. It can automatically generate filtering rules and corporate with other SDNs that support SIPD. SIPD enforced SDN can detect all the intra-AS IP spoofing packets and most of the inter-AS IP spoofing packets.