NAT: An Efficient Micro-NAT Architecture for Solving IP-Spoofing Attacks in a Corporate Network<sup>+</sup><sup>+</sup>
The Internet Protocol (IP) version 4 (IPv4) has several known vulnerabilities. One of the important vulnerabilities is that the protocol does not validate the correctness of the source address carried in an IP packet. Users with malicious intentions may take advantage of this vulnerability and launc...
Main Authors: | , , |
---|---|
Format: | Article |
Language: | English |
Published: |
MDPI AG
2020-09-01
|
Series: | Electronics |
Subjects: | |
Online Access: | https://www.mdpi.com/2079-9292/9/9/1510 |
id |
doaj-f5840d8edb9d4aa6a352a102ceec0a57 |
---|---|
record_format |
Article |
spelling |
doaj-f5840d8edb9d4aa6a352a102ceec0a572020-11-25T03:47:23ZengMDPI AGElectronics2079-92922020-09-0191510151010.3390/electronics9091510NAT: An Efficient Micro-NAT Architecture for Solving IP-Spoofing Attacks in a Corporate Network<sup>+</sup><sup>+</sup>Prakash Veeraraghavan0Dalal Hanna1Eric Pardede2Department of Computer Science and Information Technology, La Trobe University, Melbourne VIC 3086, AustraliaDepartment of Computer Science and Information Technology, La Trobe University, Melbourne VIC 3086, AustraliaDepartment of Computer Science and Information Technology, La Trobe University, Melbourne VIC 3086, AustraliaThe Internet Protocol (IP) version 4 (IPv4) has several known vulnerabilities. One of the important vulnerabilities is that the protocol does not validate the correctness of the source address carried in an IP packet. Users with malicious intentions may take advantage of this vulnerability and launch various attacks against a target host or a network. These attacks are popularly known as IP Address Spoofing attacks. One of the classical IP-spoofing attacks that cost several million dollars worldwide is the DNS-amplification attack. Currently, the availability of solutions is limited, proprietary, expensive, and requires expertise. The Internet is subjected to several other forms of amplification attacks happening every day. Even though IP-Spoofing is one of the well-researched areas since 2005, there is no holistic solution available to solve this problem from the gross-root. Also, every solution assumes that the attackers are always from outside networks. In this paper, we provide an efficient and scalable solution to solve the IP-Spoofing problem that arises from malicious or compromised inside hosts. We use a modified form of Network Address Translation (NAT) to build our solution framework. We call our framework as NAT++. The proposed infrastructure is robust, crypto-free, and easy to implement. Our simulation results have shown that the proposed NAT++ infrastructure does not consume more than the resources required by a simple NAT.https://www.mdpi.com/2079-9292/9/9/1510PrECastMicro NATDoSDNS-amplification |
collection |
DOAJ |
language |
English |
format |
Article |
sources |
DOAJ |
author |
Prakash Veeraraghavan Dalal Hanna Eric Pardede |
spellingShingle |
Prakash Veeraraghavan Dalal Hanna Eric Pardede NAT: An Efficient Micro-NAT Architecture for Solving IP-Spoofing Attacks in a Corporate Network<sup>+</sup><sup>+</sup> Electronics PrECast Micro NAT DoS DNS-amplification |
author_facet |
Prakash Veeraraghavan Dalal Hanna Eric Pardede |
author_sort |
Prakash Veeraraghavan |
title |
NAT: An Efficient Micro-NAT Architecture for Solving IP-Spoofing Attacks in a Corporate Network<sup>+</sup><sup>+</sup> |
title_short |
NAT: An Efficient Micro-NAT Architecture for Solving IP-Spoofing Attacks in a Corporate Network<sup>+</sup><sup>+</sup> |
title_full |
NAT: An Efficient Micro-NAT Architecture for Solving IP-Spoofing Attacks in a Corporate Network<sup>+</sup><sup>+</sup> |
title_fullStr |
NAT: An Efficient Micro-NAT Architecture for Solving IP-Spoofing Attacks in a Corporate Network<sup>+</sup><sup>+</sup> |
title_full_unstemmed |
NAT: An Efficient Micro-NAT Architecture for Solving IP-Spoofing Attacks in a Corporate Network<sup>+</sup><sup>+</sup> |
title_sort |
nat: an efficient micro-nat architecture for solving ip-spoofing attacks in a corporate network<sup>+</sup><sup>+</sup> |
publisher |
MDPI AG |
series |
Electronics |
issn |
2079-9292 |
publishDate |
2020-09-01 |
description |
The Internet Protocol (IP) version 4 (IPv4) has several known vulnerabilities. One of the important vulnerabilities is that the protocol does not validate the correctness of the source address carried in an IP packet. Users with malicious intentions may take advantage of this vulnerability and launch various attacks against a target host or a network. These attacks are popularly known as IP Address Spoofing attacks. One of the classical IP-spoofing attacks that cost several million dollars worldwide is the DNS-amplification attack. Currently, the availability of solutions is limited, proprietary, expensive, and requires expertise. The Internet is subjected to several other forms of amplification attacks happening every day. Even though IP-Spoofing is one of the well-researched areas since 2005, there is no holistic solution available to solve this problem from the gross-root. Also, every solution assumes that the attackers are always from outside networks. In this paper, we provide an efficient and scalable solution to solve the IP-Spoofing problem that arises from malicious or compromised inside hosts. We use a modified form of Network Address Translation (NAT) to build our solution framework. We call our framework as NAT++. The proposed infrastructure is robust, crypto-free, and easy to implement. Our simulation results have shown that the proposed NAT++ infrastructure does not consume more than the resources required by a simple NAT. |
topic |
PrECast Micro NAT DoS DNS-amplification |
url |
https://www.mdpi.com/2079-9292/9/9/1510 |
work_keys_str_mv |
AT prakashveeraraghavan natanefficientmicronatarchitectureforsolvingipspoofingattacksinacorporatenetworksupsupsupsup AT dalalhanna natanefficientmicronatarchitectureforsolvingipspoofingattacksinacorporatenetworksupsupsupsup AT ericpardede natanefficientmicronatarchitectureforsolvingipspoofingattacksinacorporatenetworksupsupsupsup |
_version_ |
1724502069127151616 |