Autonomous System based Flow Marking Scheme for IP-Traceback

被引:0
|
作者
Aghaei-Foroushani, Vahid [1 ]
Zincir-Heywood, A. Nur [1 ]
机构
[1] Dalhousie Univ, Fac Comp Sci, Halifax, NS, Canada
关键词
AS-level IP-Traceback; Flow Base IP-Traceback; Probabilistic Flow Marking; DDoS attacks; Network Security; NETWORK;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Tracing IP packets to their sources, known as IP-Traceback, is a critical task in defending against IP spoofing and DoS attacks. There are several solutions to traceback to the origin of the attack. However, all these solutions require either all routers or ISPs to support the same IP-Traceback mechanism. To address this limitation, we propose an IP-Traceback approach at the level of autonomous systems, called Autonomous System-based Flow Marking, ASFM, to identify some key locations in the path where attacker packets are being forwarded. ASFM employs the BGP update message community attribute that enables information to be passed across ASs even if they are not necessarily involved in the IP-Traceback scheme. We also propose an authentication method, so a downstream AS can examine the correctness of the marking provided by the upstream ASs, thus eliminating the fake marking embedded by subverted routers. Finally, we evaluate and analyze the performance of our proposal, using real life datasets.
引用
收藏
页码:121 / 128
页数:8
相关论文
共 50 条
  • [1] An efficient domain based marking scheme for IP traceback
    Lau, NS
    Lee, MC
    HIGH SPEED NETWORKS AND MULTIMEDIA COMMUNICATIONS, PROCEEDINGS, 2004, 3079 : 1080 - 1091
  • [2] A packet marking scheme for IP traceback
    Qu, HP
    Su, PR
    Lin, DD
    Feng, DG
    NETWORKING - ICN 2005, PT 2, 2005, 3421 : 964 - 971
  • [3] IP traceback scheme based on marking-in-order
    Qu, Hai-Peng
    Feng, Deng-Guo
    Su, Pu-Rui
    Tien Tzu Hsueh Pao/Acta Electronica Sinica, 2006, 34 (01): : 173 - 176
  • [4] Implementing Filtering and Traceback Mechanism for Packet-Marking IP-Traceback Schemes against DDoS Attacks
    Stefanidis, K.
    Serpanos, D. N.
    2008 4TH INTERNATIONAL IEEE CONFERENCE INTELLIGENT SYSTEMS, VOLS 1 AND 2, 2008, : 611 - 616
  • [5] IP traceback marking scheme based packets filtering mechanism
    Ping, SY
    Lee, MC
    2004 IEEE Workshop on IP Operations and Management Proceedings (IPOM 2004): SELF-MEASUREMENT & SELF-MANAGEMENT OF IP NETWORKS & SERVICES, 2004, : 253 - 260
  • [6] A novel packet marking scheme for IP traceback
    Al-Duwairi, B
    Manimaran, G
    TENTH INTERNATIONAL CONFERENCE ON PARALLEL AND DISTRIBUTED SYSTEMS, PROCEEDINGS, 2004, : 195 - 202
  • [7] Tabu marking scheme to speedup IP traceback
    Ma, Miao
    COMPUTER NETWORKS, 2006, 50 (18) : 3536 - 3549
  • [8] Deterministic and Authenticated Flow Marking for IP Traceback
    Foroushani, Vahid Aghaei
    Zincir-Heywood, A. Nur
    2013 IEEE 27TH INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION NETWORKING AND APPLICATIONS (AINA), 2013, : 397 - 404
  • [9] Probabilistic Flow Marking for IP Traceback (PFM)
    Aghaei-Foroushani, Vahid
    Zincir-Heywood, A. Nur
    2015 7TH INTERNATIONAL WORKSHOP ON RELIABLE NETWORKS DESIGN AND MODELING (RNDM) PROCE4EDINGS, 2015, : 229 - 236
  • [10] A Fast Deterministic Packet Marking Scheme for IP Traceback
    Wang Xiao-jing
    Hu Chang-zhen
    Hu He
    MINES 2009: FIRST INTERNATIONAL CONFERENCE ON MULTIMEDIA INFORMATION NETWORKING AND SECURITY, VOL 2, PROCEEDINGS, 2009, : 526 - 529