Source Address Validation
arXiv:2301.09952 · doi:10.1007/978-3-642-27739-9_1626-1
Abstract
Source address validation (SAV) is a standard formalized in RFC 2827 aimed at discarding packets with spoofed source IP addresses. The absence of SAV has been known as a root cause of reflection distributed denial-of-service (DDoS) attacks. Outbound SAV (oSAV): filtering applied at the network edge to traffic coming from inside the customer network to the outside. Inbound SAV (iSAV): filtering applied at the network edge to traffic coming from the outside to the customer network.
arXiv admin note: substantial text overlap with arXiv:2006.05277, arXiv:2002.00441