共 50 条
Internet attack traceback - Cross-Validation and pebble tracing
被引:1
|作者:
Yu, Fang
[1
]
Lee, David
[1
]
机构:
[1] Ohio State Univ, Dept Comp Sci & Engn, Columbus, OH 43210 USA
关键词:
D O I:
10.1109/THS.2008.4534481
中图分类号:
TP39 [计算机的应用];
学科分类号:
081203 ;
0835 ;
摘要:
It is of strategic importance for our cyber space security to be able to trace back to the origin of an Internet attack However, it is particularly challenging due to the evading techniques that attackers use: IP spoofing and attacking across stepping stones. A number of attack traceback methods have been proposed, most of them deal with DoSIDDoS attacks or do not perform well in a non-cooperate or hostile environment. In this contribution, we propose a single packet and host-based traceback scheme. It consists of two phases: Cross-Validation for coping with IP spoofing; and Pebble-Trace for uncovering original attack host location. Cross-Validation is the process that a validation server analyzes an attack packet and determines whether its source IP address is spoofedfor making a decision on the feasibility and strategy of traceback. If a source IP address is invalid, we can only black-list and block it. Otherwise, we propose a new technique called Pebble-Trace to uncover the attack original source by probing packets. While a probing packet from the validation server traverses through stepping stones to the attacker it spreads tracing packets on its way, which "report" the IP address of the machine that it traverses (or its payload passes) through back to the validation server. All the trace operations are done automatically and secretly to prevent the attacker from detecting and evading the process.
引用
收藏
页码:378 / 383
页数:6
相关论文