In contrast to host-based solutions, router-based defense mechanisms are
able to address the fundamental weakness which allows IP spoofing. Packets
with a forged source address can successfully reach their destination because
routers only use the destination address of packets to deliver them and do
not verify the source address of packets. Preventive router-based solutions can
either provide a way for routers to verify the source address of packets based
on their incoming direction, or use some marking to identify the true source of
a packet. This allows routers to detect and drop spoofing packets closer to an
attacker, before the packets even reach end-hosts.