IP Address Spoofing - Defense Against Spoofing Attacks

Defense Against Spoofing Attacks

Packet filtering is one defense against IP spoofing attacks. The gateway to a network usually performs ingress filtering, which is blocking of packets from outside the network with a source address inside the network. This prevents an outside attacker spoofing the address of an internal machine. Ideally the gateway would also perform egress filtering on outgoing packets, which is blocking of packets from inside the network with a source address that is not inside. This prevents an attacker within the network performing filtering from launching IP spoofing attacks against external machines.

It is also recommended to design network protocols and services so that they do not rely on the IP source address for authentication.

Read more about this topic:  IP Address Spoofing

Famous quotes containing the words defense and/or attacks:

    Our reliance is in the love of liberty which God has planted in our bosoms. Our defense is in the preservation of the spirit which prizes liberty as the heritage of all men, in all lands, every where.
    Abraham Lincoln (1809–1865)

    We are seeing an increasing level of attacks on the “selfishness” of women. There are allegations that all kinds of social ills, from runaway children to the neglected elderly, are due to the fact that women have left their “rightful” place in the home. Such arguments are simplistic and wrongheaded but women are especially vulnerable to the accusation that if society has problems, it’s because women aren’t nurturing enough.
    Grace Baruch (20th century)