NSDI 26 - EZ-SAVE: Evaluation of Easy-to-Deploy Source Address Validation Policies @UsenixOrg
NSDI 26 - EZ-SAVE: Evaluation of Easy-to-Deploy Source Address Validation Policies  @UsenixOrg
Uploaded June 2026 | Updated September 2026, 3 weeks ago
NSDI '26 - EZ-SAVE: Evaluation of Easy-to-Deploy Source Address Validation Policies

Nicholas Scaglione and Justin Furuness, University of Connecticut; Yossi Gilad, Hebrew University of Jerusalem; Hemi Leibowitz, The College of Management Academic Studies; Cameron Morris and Bing Wang, University of Connecticut; Kotikalapudi Sriram, National Institute of Standards and Technology (NIST); Amir Herzberg, University of Connecticut

The lack of Source Address Validation (SAV) is a significant vulnerability of the Internet, which is abused in many Denial-of-Service (DoS) and other attacks. Several IETF RFCs define easy-to-deploy, non-interactive SAV designs; the IETF is currently developing another SAV mechanism, BAR-SAV, which, as its name suggests, uses BGP, ASPA (Autonomous System Provider Authorization), and ROA (Route Origin Authorization) data. However, no comparative evaluation of the potential impact of their large-scale deployment has been done. A recent survey of network vendors and operators indicates that more efficacy data and usage guidelines are necessary to motivate their adoption.

We present EZ-SAVE, the first simulation-based analysis evaluating easy-to-deploy SAV policies. We measure both the spoofed traffic detection rates and the legitimate traffic filtering (false-positive) rates for each standard and proposed design at different adoption rates, using a realistic Internet topology and traffic engineering policies. Our results reveal several significant insights that may assist and guide the standardization process as well as developers and operators. In particular, we find that BAR-SAV proves to be the most effective design that features high spoof detection rates and low (or even zero) false-positive rates, motivating its standardization and deployment. Our results also provide operators with guidance on other SAV mechanisms that are effective for specific scenarios. In addition, our results highlight the importance of using realistic export policies for SAV evaluation.

View the full NSDI '26 program at usenix.org/conference/nsdi26/technical-sessions
NSDI 26 - EZ-SAVE: Evaluation of Easy-to-Deploy Source Address Validation PoliciesNSDI 26- Bridging Storage and Execution: A Semantic Virtual Bus for On-Demand Application StreamingPEPR 26 - Mapping the Privacy Workforce in the AI EraNSDI 26 - EROICA: Online Performance Troubleshooting for Large-scale Model TrainingNSDI 26 - CrossCheck: Input Validation for WAN Control SystemsNSDI 26 - Controlling Arbitrary Internet Queues with TitrateNSDI 26 - Learning to Tune Optical WANs: A Field Deployment of Noise Models in Optical NetworksNSDI 26 - SYMPHONY: Enabling Compute-Memory Disaggregation in LLM Serving SystemsPEPR 26 - Provenance Without Surveillance: Privacy Engineering for AI Content TransparencyNSDI 26 - A Fast Solver-Free Algorithm for Traffic Engineering in Large-Scale Data Center NetworkNSDI 26 - Building A CSFQ-Inspired Transport for Switched CXL Memory PoolingSREcon24 Europe/Middle East/Africa - Noisy Neighbors, through Networking
USENIX |

NSDI '26 - EZ-SAVE: Evaluation of Easy-to-Deploy Source Address Validation Policies

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER