Autonomous System based Flow Marking Scheme for IP-Traceback

被引:0
|
作者
Aghaei-Foroushani, Vahid [1 ]
Zincir-Heywood, A. Nur [1 ]
机构
[1] Dalhousie Univ, Fac Comp Sci, Halifax, NS, Canada
关键词
AS-level IP-Traceback; Flow Base IP-Traceback; Probabilistic Flow Marking; DDoS attacks; Network Security; NETWORK;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Tracing IP packets to their sources, known as IP-Traceback, is a critical task in defending against IP spoofing and DoS attacks. There are several solutions to traceback to the origin of the attack. However, all these solutions require either all routers or ISPs to support the same IP-Traceback mechanism. To address this limitation, we propose an IP-Traceback approach at the level of autonomous systems, called Autonomous System-based Flow Marking, ASFM, to identify some key locations in the path where attacker packets are being forwarded. ASFM employs the BGP update message community attribute that enables information to be passed across ASs even if they are not necessarily involved in the IP-Traceback scheme. We also propose an authentication method, so a downstream AS can examine the correctness of the marking provided by the upstream ASs, thus eliminating the fake marking embedded by subverted routers. Finally, we evaluate and analyze the performance of our proposal, using real life datasets.
引用
收藏
页码:121 / 128
页数:8
相关论文
共 50 条
  • [41] Advanced and authenticated marking schemes for IP traceback
    Song, DXD
    Perrig, A
    IEEE INFOCOM 2001: THE CONFERENCE ON COMPUTER COMMUNICATIONS, VOLS 1-3, PROCEEDINGS: TWENTY YEARS INTO THE COMMUNICATIONS ODYSSEY, 2001, : 878 - 886
  • [42] Enhanced Probabilistic packet marking for IP traceback
    Gao, ZQ
    Ansari, N
    GLOBECOM '05: IEEE GLOBAL TELECOMMUNICATIONS CONFERENCE, VOLS 1-6: DISCOVERY PAST AND FUTURE, 2005, : 1676 - 1680
  • [43] RIM: Router Interface Marking for IP Traceback
    Chen, Ruiliang
    Park, Jung-Min
    Marchany, Randolph
    GLOBECOM 2006 - 2006 IEEE GLOBAL TELECOMMUNICATIONS CONFERENCE, 2006,
  • [44] Tagged Fragment Marking Scheme with distance-weighted sampling for a fast IP traceback
    Kim, KC
    Hwang, JS
    Kim, BY
    Kim, SD
    WEB TECHNOLOGIES AND APPLICATIONS, 2003, 2642 : 442 - 452
  • [45] Distributed-log-based scheme for IP traceback
    Jing, YN
    Tu, P
    Wang, XP
    Zhang, GD
    Fifth International Conference on Computer and Information Technology - Proceedings, 2005, : 711 - 715
  • [46] A Precise and Practical IP Traceback Technique Based on Packet Marking and Logging
    Yan, Dong
    Wang, Yulong
    Su, Sen
    Yang, Fangchun
    JOURNAL OF INFORMATION SCIENCE AND ENGINEERING, 2012, 28 (03) : 453 - 470
  • [47] Ip traceback using flow based classification
    Bhavani Y.
    Janaki V.
    Sridevi R.
    Recent Advances in Computer Science and Communications, 2020, 13 (03) : 482 - 490
  • [48] A Hybrid Messaging-Based Scheme for IP Traceback
    Fadlallah, Ahmad
    Serhrouchni, Ahmed
    Begriche, Youcef
    Nait-Abdesselam, Farid
    2008 3RD INTERNATIONAL CONFERENCE ON INFORMATION AND COMMUNICATION TECHNOLOGIES: FROM THEORY TO APPLICATIONS, VOLS 1-5, 2008, : 2543 - +
  • [49] Fast and secure probabilistic marking technology for IP traceback
    Tian, Hongcheng
    Bi, Jun
    Jiang, Xiaoke
    Wang, Dekai
    Zhang, Wei
    Qinghua Daxue Xuebao/Journal of Tsinghua University, 2011, 51 (04): : 542 - 547
  • [50] Toward a practical packet marking approach for IP traceback
    Gong, Chao
    Sarac, Kamil
    International Journal of Network Security, 2009, 8 (03): : 271 - 281