An Incrementally Deployable Flow-Based Scheme for IP Traceback

被引:16
|
作者
Tian, Hongcheng [1 ]
Bi, Jun [1 ]
机构
[1] Tsinghua Univ, Network Res Ctr, Beijing 100084, Peoples R China
基金
高等学校博士学科点专项科研基金; 美国国家科学基金会;
关键词
IP traceback; flow; overlay network;
D O I
10.1109/LCOMM.2012.051512.120467
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
IP traceback can be used to find the origins and paths of attacking traffic. However, so far, most approaches for IP traceback are hard to be deployed in the Internet because of deployment difficulties. In this paper, we present an incrementally deployable approach based on sampled flows for IP traceback (SampleTrace). In SampleTrace, it is not necessary to deploy any dedicated traceback software and hardware at routers, and an AS-level overlay network is built for incremental deployment. We theoretically analyze the quantitative relation among the probability that a flow is successfully traced back various AS-level hop number, independently sampling probability, and the packet number that the attacking flow comprises. According to Bernoulli's Law of Large Numbers, when a large number of attacking flows are practically traced back in the Internet by SampleTrace, the successfully-traced back relative frequency will approach the successfully-traced back probability.
引用
收藏
页码:1140 / 1143
页数:4
相关论文
共 50 条
  • [11] A Hybrid Messaging-Based Scheme for IP Traceback
    Fadlallah, Ahmad
    Serhrouchni, Ahmed
    Begriche, Youcef
    Nait-Abdesselam, Farid
    2008 3RD INTERNATIONAL CONFERENCE ON INFORMATION AND COMMUNICATION TECHNOLOGIES: FROM THEORY TO APPLICATIONS, VOLS 1-5, 2008, : 2543 - +
  • [12] A packet marking scheme for IP traceback
    Qu, HP
    Su, PR
    Lin, DD
    Feng, DG
    NETWORKING - ICN 2005, PT 2, 2005, 3421 : 964 - 971
  • [13] An Efficient and Adaptive IP Traceback Scheme
    Iwamoto, Kayoko
    Soshi, Masakazu
    Satoh, Takashi
    2014 IEEE 7TH INTERNATIONAL CONFERENCE ON SERVICE-ORIENTED COMPUTING AND APPLICATIONS (SOCA), 2014, : 235 - 240
  • [14] IP traceback marking scheme based packets filtering mechanism
    Ping, SY
    Lee, MC
    2004 IEEE Workshop on IP Operations and Management Proceedings (IPOM 2004): SELF-MEASUREMENT & SELF-MANAGEMENT OF IP NETWORKS & SERVICES, 2004, : 253 - 260
  • [15] RIHT: A Novel Hybrid IP Traceback Scheme
    Yang, Ming-Hour
    Yang, Ming-Chien
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2012, 7 (02) : 789 - 797
  • [16] An IP traceback scheme integrating DPM and PPM
    Min, F
    Zhang, JY
    Yang, GW
    APPLIED CRYPTOGRAPHY AND NETWORK SECURITY, PROCEEDINGS, 2003, 2846 : 76 - 85
  • [17] A novel packet marking scheme for IP traceback
    Al-Duwairi, B
    Manimaran, G
    TENTH INTERNATIONAL CONFERENCE ON PARALLEL AND DISTRIBUTED SYSTEMS, PROCEEDINGS, 2004, : 195 - 202
  • [18] Tabu marking scheme to speedup IP traceback
    Ma, Miao
    COMPUTER NETWORKS, 2006, 50 (18) : 3536 - 3549
  • [19] An Overview of IP Flow-Based Intrusion Detection
    Sperotto, Anna
    Schaffrath, Gregor
    Sadre, Ramin
    Morariu, Cristian
    Pras, Aiko
    Stiller, Burkhard
    IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2010, 12 (03): : 343 - 356
  • [20] A Lightweight IP Traceback Scheme Depending on TTL
    Yan Fen
    Zhu Hui
    Chen Shuang-shuang
    Yin Xin-chun
    2012 INTERNATIONAL WORKSHOP ON INFORMATION AND ELECTRONICS ENGINEERING, 2012, 29 : 1932 - 1937