Deployment of Source Address Validation by Network Operators: A Randomized Control Trial

IEEE Symposium on Security and Privacy (S&P)(2022)

引用 10|浏览23
暂无评分
摘要
IP spoofing, sending IP packets with a false source IP address, continues to be a primary attack vector for largescale Denial of Service attacks. To combat spoofing, various interventions have been tried to increase the adoption of source address validation (SAV) among network operators. How can SAV deployment be increased? In this work, we conduct the first randomized control trial to measure the effectiveness of various notification mechanisms on SAV deployment. We include new treatments using nudges and channels, previously untested in notification experiments. Our design reveals a painful reality that contrasts with earlier observational studies: none of the notification treatments significantly improved SAV deployment compared to the control group. We explore the reasons for these findings and report on a survey among operators to identify ways forward. A portion of the operators indicate that they do plan to deploy SAV and ask for better notification mechanisms, training, and support materials for SAV implementation.
更多
查看译文
关键词
IP spoofing,IP packets,false source IP address,primary attack vector,source address validation deployment,large-scale denial of service attacks
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要