Branch label based probabilistic packet marking for counteracting DDoS attacks

被引:0
|
作者
Ogawa, T [1 ]
Nakamura, F
Wakahara, Y
机构
[1] Hewlett Packard Japan Ltd, Tokyo 1688585, Japan
[2] Univ Tokyo, Grad Sch Frontier Sci, Tokyo 1130033, Japan
关键词
branch label; route label; probabilistic packet marking; IP traceback; IP spoofing; DDoS attacks;
D O I
暂无
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Effective counteraction to Distributed Denial-of-Services (DDoS) attacks is a pressing problem over the Internet. For this counteraction, it is considered important to locate the router interfaces closest to the attackers in order to effectively filter a great number of identification jammed packets with spoofed source addresses from widely distributed area. Edge sample (ES) based Probabilistic Packet Marking (PPM) is an encouraging method to cope with source IP spoofing, which usually accompanies DDoS attacks. But its fragmentation of path information leads to inefficiency in terms of necessary number of packets, path calculation time and identification accuracy. We propose Branch Label (BL) based PPM to solve the above inefficiency problem. In BL, a whole single path information is marked in a packet without fragmentation in contrast to ES based PPM. The whole path information in packets by the BL approach is expressed with branch information of each router interfaces. This brings the following three key advantages in the process of detecting the interfaces: quick increase in true-positives detected (efficiency), quick decrease in false-negatives detected (accuracy) and fast convergence (quickness).
引用
收藏
页码:1900 / 1909
页数:10
相关论文
共 50 条
  • [21] A traceback approach with probabilistic packet marking IP based on cooperations
    Yan, D. (yandong200@gmail.com), 1600, Beijing University of Posts and Telecommunications (35):
  • [22] Entropy Based Detection of DDoS Attacks in Packet Switching Network Models
    Lawniczak, Anna T.
    Wu, Hao
    Di Stefano, Bruno
    COMPLEX SCIENCES, PT 2, 2009, 5 : 1810 - +
  • [23] Step-tracking Algorithm of DDoS Attacks Based on Advanced Marking Scheme
    Yang Xueqin
    Yang Xuehui
    Chen Chaobo
    PROCEEDINGS OF THE 2016 3RD INTERNATIONAL CONFERENCE ON MECHATRONICS AND INFORMATION TECHNOLOGY (ICMIT), 2016, 49 : 43 - 48
  • [24] Implementing Filtering and Traceback Mechanism for Packet-Marking IP-Traceback Schemes against DDoS Attacks
    Stefanidis, K.
    Serpanos, D. N.
    2008 4TH INTERNATIONAL IEEE CONFERENCE INTELLIGENT SYSTEMS, VOLS 1 AND 2, 2008, : 611 - 616
  • [25] On Improving an Algebraic Marking Scheme for Detecting DDoS Attacks
    Lee, Moon-Chuen
    He, Yi-Jun
    Chen, Zhaole
    JOURNAL OF INFORMATION ASSURANCE AND SECURITY, 2008, 3 (04): : 279 - 288
  • [26] Effective packet marking approach to defend against DDoS attack
    Lim, H
    Hong, M
    COMPUTATIONAL SCIENCE AND ITS APPLICATIONS - ICCSA 2004, PT 4, 2004, 3046 : 708 - 716
  • [27] Effective packet marking approach to defend against DDoS attack
    Lim, H
    Hong, M
    8TH WORLD MULTI-CONFERENCE ON SYSTEMICS, CYBERNETICS AND INFORMATICS, VOL IX, PROCEEDINGS: COMPUTER SCIENCE AND ENGINEERING: I, 2004, : 179 - 183
  • [28] An IP-traceback-based packet filtering scheme for eliminating DDoS attacks
    Wang, Yulong
    Sun, Rui
    Journal of Networks, 2014, 9 (04) : 874 - 881
  • [29] Enhanced Probabilistic packet marking for IP traceback
    Gao, ZQ
    Ansari, N
    GLOBECOM '05: IEEE GLOBAL TELECOMMUNICATIONS CONFERENCE, VOLS 1-6: DISCOVERY PAST AND FUTURE, 2005, : 1676 - 1680
  • [30] The evaluation of the probabilistic packet marking for path bifurcation
    Fu, JM
    Zhu, Q
    Zhang, HG
    DCABES 2004, Proceedings, Vols, 1 and 2, 2004, : 182 - 185