NAT: An Efficient Micro-NAT Architecture for Solving IP-Spoofing Attacks in a Corporate Network<sup>+</sup><sup>+</sup>

The Internet Protocol (IP) version 4 (IPv4) has several known vulnerabilities. One of the important vulnerabilities is that the protocol does not validate the correctness of the source address carried in an IP packet. Users with malicious intentions may take advantage of this vulnerability and launc...

Full description

Bibliographic Details
Main Authors: Prakash Veeraraghavan, Dalal Hanna, Eric Pardede
Format: Article
Language:English
Published: MDPI AG 2020-09-01
Series:Electronics
Subjects:
DoS
Online Access:https://www.mdpi.com/2079-9292/9/9/1510
id doaj-f5840d8edb9d4aa6a352a102ceec0a57
record_format Article
spelling doaj-f5840d8edb9d4aa6a352a102ceec0a572020-11-25T03:47:23ZengMDPI AGElectronics2079-92922020-09-0191510151010.3390/electronics9091510NAT: An Efficient Micro-NAT Architecture for Solving IP-Spoofing Attacks in a Corporate Network<sup>+</sup><sup>+</sup>Prakash Veeraraghavan0Dalal Hanna1Eric Pardede2Department of Computer Science and Information Technology, La Trobe University, Melbourne VIC 3086, AustraliaDepartment of Computer Science and Information Technology, La Trobe University, Melbourne VIC 3086, AustraliaDepartment of Computer Science and Information Technology, La Trobe University, Melbourne VIC 3086, AustraliaThe Internet Protocol (IP) version 4 (IPv4) has several known vulnerabilities. One of the important vulnerabilities is that the protocol does not validate the correctness of the source address carried in an IP packet. Users with malicious intentions may take advantage of this vulnerability and launch various attacks against a target host or a network. These attacks are popularly known as IP Address Spoofing attacks. One of the classical IP-spoofing attacks that cost several million dollars worldwide is the DNS-amplification attack. Currently, the availability of solutions is limited, proprietary, expensive, and requires expertise. The Internet is subjected to several other forms of amplification attacks happening every day. Even though IP-Spoofing is one of the well-researched areas since 2005, there is no holistic solution available to solve this problem from the gross-root. Also, every solution assumes that the attackers are always from outside networks. In this paper, we provide an efficient and scalable solution to solve the IP-Spoofing problem that arises from malicious or compromised inside hosts. We use a modified form of Network Address Translation (NAT) to build our solution framework. We call our framework as NAT++. The proposed infrastructure is robust, crypto-free, and easy to implement. Our simulation results have shown that the proposed NAT++ infrastructure does not consume more than the resources required by a simple NAT.https://www.mdpi.com/2079-9292/9/9/1510PrECastMicro NATDoSDNS-amplification
collection DOAJ
language English
format Article
sources DOAJ
author Prakash Veeraraghavan
Dalal Hanna
Eric Pardede
spellingShingle Prakash Veeraraghavan
Dalal Hanna
Eric Pardede
NAT: An Efficient Micro-NAT Architecture for Solving IP-Spoofing Attacks in a Corporate Network<sup>+</sup><sup>+</sup>
Electronics
PrECast
Micro NAT
DoS
DNS-amplification
author_facet Prakash Veeraraghavan
Dalal Hanna
Eric Pardede
author_sort Prakash Veeraraghavan
title NAT: An Efficient Micro-NAT Architecture for Solving IP-Spoofing Attacks in a Corporate Network<sup>+</sup><sup>+</sup>
title_short NAT: An Efficient Micro-NAT Architecture for Solving IP-Spoofing Attacks in a Corporate Network<sup>+</sup><sup>+</sup>
title_full NAT: An Efficient Micro-NAT Architecture for Solving IP-Spoofing Attacks in a Corporate Network<sup>+</sup><sup>+</sup>
title_fullStr NAT: An Efficient Micro-NAT Architecture for Solving IP-Spoofing Attacks in a Corporate Network<sup>+</sup><sup>+</sup>
title_full_unstemmed NAT: An Efficient Micro-NAT Architecture for Solving IP-Spoofing Attacks in a Corporate Network<sup>+</sup><sup>+</sup>
title_sort nat: an efficient micro-nat architecture for solving ip-spoofing attacks in a corporate network<sup>+</sup><sup>+</sup>
publisher MDPI AG
series Electronics
issn 2079-9292
publishDate 2020-09-01
description The Internet Protocol (IP) version 4 (IPv4) has several known vulnerabilities. One of the important vulnerabilities is that the protocol does not validate the correctness of the source address carried in an IP packet. Users with malicious intentions may take advantage of this vulnerability and launch various attacks against a target host or a network. These attacks are popularly known as IP Address Spoofing attacks. One of the classical IP-spoofing attacks that cost several million dollars worldwide is the DNS-amplification attack. Currently, the availability of solutions is limited, proprietary, expensive, and requires expertise. The Internet is subjected to several other forms of amplification attacks happening every day. Even though IP-Spoofing is one of the well-researched areas since 2005, there is no holistic solution available to solve this problem from the gross-root. Also, every solution assumes that the attackers are always from outside networks. In this paper, we provide an efficient and scalable solution to solve the IP-Spoofing problem that arises from malicious or compromised inside hosts. We use a modified form of Network Address Translation (NAT) to build our solution framework. We call our framework as NAT++. The proposed infrastructure is robust, crypto-free, and easy to implement. Our simulation results have shown that the proposed NAT++ infrastructure does not consume more than the resources required by a simple NAT.
topic PrECast
Micro NAT
DoS
DNS-amplification
url https://www.mdpi.com/2079-9292/9/9/1510
work_keys_str_mv AT prakashveeraraghavan natanefficientmicronatarchitectureforsolvingipspoofingattacksinacorporatenetworksupsupsupsup
AT dalalhanna natanefficientmicronatarchitectureforsolvingipspoofingattacksinacorporatenetworksupsupsupsup
AT ericpardede natanefficientmicronatarchitectureforsolvingipspoofingattacksinacorporatenetworksupsupsupsup
_version_ 1724502069127151616