Hop Integrity in Computer Networks ∗
Abstract:
A computer network is said to provide hop integrity iff when any router p in the network receives a message m supposedly from an adjacent router q, then p can check that m was indeed sent by q, was not modified after it was sent, and was not a replay of an old message sent from q to p. In this paper, we describe three protocols that can be added to the routers in a computer network so that the network can provide hop integrity. These three protocols are a secret exchange protocol, a weak integrity protocol, and a strong integrity protocol. All three protocols are stateless, require small overhead, and do not constrain the network protocol in the routers in any way. 1.
Citations
| 314 | Network ingress filtering: Defeating denial of service attacks which employ IP source address spoofing – Ferguson, Senie |
| 143 | Security Architecture for the Internet – Kent, Atkinson - 1998 |
| 57 | An efficient message authentication scheme for link state routing – Cheung - 1997 |
| 57 | Internetworking with TCP/IP, Vol – Comer, Stevens - 1999 |
| 46 | Elements of Network Protocol Design – Gouda - 1998 |
| 44 | A Simple Active Attack Against TCP – Joncheray - 1995 |
| 12 | Hop integrity in computer networks – Gouda, Elnozahy, et al. - 2002 |
| 4 | Digital Signature Protection of OSPF Routing – Murphy, Badger - 1996 |
| 3 | Garcia-Luna-Aceves, “Securing distance vector routing protocols – Smith, Murthy, et al. - 1997 |
| 2 | Internet Security Attacks at the Basic – Vivo, Vivo, et al. - 1998 |

