A marking scheme using Huffman codes for IP traceback

被引:0
|
作者
Choi, KH [1 ]
Dai, HK [1 ]
机构
[1] Oklahoma State Univ, Dept Comp Sci, Stillwater, OK 74078 USA
关键词
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
In (Distributed) Denial of Service attack ((D)DoS), attackers send a huge number of packets with spoofed source addresses to disguise themselves toward a target host or network. Various IP traceback techniques such as link testing, marking, and logging to find out the real source of attacking packets have been proposed. We present a new marking scheme (with marking and traceback algorithms) in which a router marks a packet with a link that the packet came through. Links of a router are represented by Huffman codes according to the traffic distribution among the links. If the packet runs out of space allotted for the marking field in the packet header then the router stores the marking field in the router's local memory along with a message digest of the packet. We analyze the memory requirement of routers to store marking fields, compare the new scheme with other existing techniques, and address practical issues to deploy the new scheme in the Internet. The new scheme marks every packet, therefore IP traceback can be accomplished with only a packet unlike in probabilistic markings; also it requires far less amount of memory compared to logging methods and is robust in case of DDoS.
引用
收藏
页码:421 / 428
页数:8
相关论文
共 50 条
  • [31] Tagged Fragment Marking Scheme with distance-weighted sampling for a fast IP traceback
    Kim, KC
    Hwang, JS
    Kim, BY
    Kim, SD
    WEB TECHNOLOGIES AND APPLICATIONS, 2003, 2642 : 442 - 452
  • [32] Fast and secure probabilistic marking technology for IP traceback
    Tian, Hongcheng
    Bi, Jun
    Jiang, Xiaoke
    Wang, Dekai
    Zhang, Wei
    Qinghua Daxue Xuebao/Journal of Tsinghua University, 2011, 51 (04): : 542 - 547
  • [33] Toward a practical packet marking approach for IP traceback
    Gong, Chao
    Sarac, Kamil
    International Journal of Network Security, 2009, 8 (03): : 271 - 281
  • [34] Advanced packet marking mechanism with pushback for IP traceback
    Lee, HW
    APPLIED CRYPTOGRAPHY AND NETWORK SECURITY, PROCEEDINGS, 2004, 3089 : 426 - 438
  • [35] Survey on Packet Marking Fields and Information for IP Traceback
    Vasseur, Marion
    Khatoun, Rida
    Serhrouchni, Ahmed
    2015 INTERNATIONAL CONFERENCE ON PROTOCOL ENGINEERING (ICPE) AND INTERNATIONAL CONFERENCE ON NEW TECHNOLOGIES OF DISTRIBUTED SYSTEMS (NTDS), 2015,
  • [36] Enhanced and authenticated deterministic packet marking for IP traceback
    Peng, Dan
    Shi, Zhicai
    Tao, Longming
    Ma, Wu
    ADVANCED PARALLEL PROCESSING TECHNOLOGIES, PROCEEDINGS, 2007, 4847 : 508 - 517
  • [37] Modifications of Probabilistic packet marking schemes for IP traceback
    Lin, JH
    Xiao, W
    8TH WORLD MULTI-CONFERENCE ON SYSTEMICS, CYBERNETICS AND INFORMATICS, VOL XI, PROCEEDINGS: CONTROL, COMMUNICATION AND NETWORK SYSTEMS, TECHNOLOGIES AND APPLICATIONS, 2004, : 89 - 91
  • [38] Two novel packet marking schemes for IP traceback
    Hu, Hanping
    Wang, Yi
    Wang, Lingfei
    Guo, Wenxuan
    Ding, Mingyue
    AUTONOMIC AND TRUSTED COMPUTING, PROCEEDINGS, 2006, 4158 : 459 - 466
  • [39] IP Traceback based on Deterministic Packet Marking and Logging
    Wang Xiao-jing
    Xiao You-lin
    2009 INTERNATIONAL CONFERENCE ON SCALABLE COMPUTING AND COMMUNICATIONS & EIGHTH INTERNATIONAL CONFERENCE ON EMBEDDED COMPUTING, 2009, : 178 - +
  • [40] Accommodating fragmentation in deterministic packet marking for IP traceback
    Belenky, A
    Ansari, N
    GLOBECOM'03: IEEE GLOBAL TELECOMMUNICATIONS CONFERENCE, VOLS 1-7, 2003, : 1374 - 1378