IP spoofing enables reflection and amplification attacks, which cause major threats to the current Internet infrastructure. Detecting IP packets with incorrect source addresses would help to improve the situation. This is easy at the attacker's network, but very challenging at Internet eXchange Points (IXPs) or in transit networks. In this reproducibility study, we revisit the paper \textit{Detection, Classification, and Analysis of Inter-Domain Traffic with Spoofed Source IP Addresses} published at ACM IMC 2017. Using data from a different IXP and from a different time, we were not able to reproduce the results. Unfortunately, our further analysis reveals structural problems of the state of the art methodology, which are not easy to overcome.
翻译:IP Spoofing 能够进行反射和放大攻击,这些攻击对目前的互联网基础设施造成重大威胁。 检测有不正确的源地址的IP包将有助于改善这种状况。 这在攻击者的网络上很容易,但在互联网的 eXchange points (IXPs) 或 中转网络上非常困难。 在这项可复制性研究中,我们重新审视了AM IMC 2017 上发表的论文 \ textit{ Spoofed源的IP地址的检测、分类和分析。 使用来自不同源代码的来自不同时间的 IXP 的数据, 我们无法复制结果。 不幸的是, 我们的进一步分析揭示了现代方法的结构问题, 这些问题不容易克服。