A marking scheme using Huffman codes for IP traceback

被引:0
|
作者
Choi, KH [1 ]
Dai, HK [1 ]
机构
[1] Oklahoma State Univ, Dept Comp Sci, Stillwater, OK 74078 USA
来源
I-SPAN 2004: 7TH INTERNATIONAL SYMPOSIUM ON PARALLEL ARCHITECTURES, ALGORITHMS AND NETWORKS, PROCEEDINGS | 2004年
关键词
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
In (Distributed) Denial of Service attack ((D)DoS), attackers send a huge number of packets with spoofed source addresses to disguise themselves toward a target host or network. Various IP traceback techniques such as link testing, marking, and logging to find out the real source of attacking packets have been proposed. We present a new marking scheme (with marking and traceback algorithms) in which a router marks a packet with a link that the packet came through. Links of a router are represented by Huffman codes according to the traffic distribution among the links. If the packet runs out of space allotted for the marking field in the packet header then the router stores the marking field in the router's local memory along with a message digest of the packet. We analyze the memory requirement of routers to store marking fields, compare the new scheme with other existing techniques, and address practical issues to deploy the new scheme in the Internet. The new scheme marks every packet, therefore IP traceback can be accomplished with only a packet unlike in probabilistic markings; also it requires far less amount of memory compared to logging methods and is robust in case of DDoS.
引用
收藏
页码:421 / 428
页数:8
相关论文
共 50 条
  • [41] Survey on Packet Marking Fields and Information for IP Traceback
    Vasseur, Marion
    Chen, Xiuzhen
    Khatoun, Rida
    Serhrouchni, Ahmed
    2015 INTERNATIONAL CONFERENCE ON CYBER SECURITY OF SMART CITIES, INDUSTRIAL CONTROL AND COMMUNICATIONS (SSIC), 2015,
  • [42] Deterministic Packet Marking with Link Signatures for IP traceback
    Shi Yi
    Yang Xinyu
    Li Ning
    Qi Yong
    INFORMATION SECURITY AND CRYPTOLOGY, PROCEEDINGS, 2006, 4318 : 144 - +
  • [43] An Efficient and Adaptive IP Traceback Scheme
    Iwamoto, Kayoko
    Soshi, Masakazu
    Satoh, Takashi
    2014 IEEE 7TH INTERNATIONAL CONFERENCE ON SERVICE-ORIENTED COMPUTING AND APPLICATIONS (SOCA), 2014, : 235 - 240
  • [44] Dynamic probabilistic packet marking for efficient IP traceback
    Liu, Jenshiuh
    Lee, Zhi-Jian
    Chung, Yeh-Ching
    COMPUTER NETWORKS, 2007, 51 (03) : 866 - 882
  • [45] An implementation of IP traceback in IPv6 using probabilistic packet marking
    Albright, E
    Dang, XH
    ICOMP '05: PROCEEDINGS OF THE 2005 INTERNATIONAL CONFERENCE ON INTERNET COMPUTING, 2005, : 416 - 421
  • [46] IP traceback by packet marking method with bloom filters
    Takurou, Hosoi
    Matsuura, Kanta
    Mai, Hideki
    41ST ANNUAL IEEE INTERNATIONAL CARNAHAN CONFERENCE ON SECURITY TECHNOLOGY, PROCEEDINGS, 2007, : 255 - +
  • [47] Packet Marking With Distance Based Probabilities for IP Traceback
    Akyuz, Turker
    Sogukpinar, Ibrahim
    2009 FIRST INTERNATIONAL CONFERENCE ON NETWORKS & COMMUNICATIONS (NETCOM 2009), 2009, : 433 - 438
  • [48] DDPM:Dynamic deterministic packet marking for IP traceback
    Shokri, Reza
    Varshovi, Ali
    Mohammadi, Hossein
    Yazdani, Nasser
    Sadeghian, Babak
    ICON: 2006 IEEE INTERNATIONAL CONFERENCE ON NETWORKS, VOLS 1 AND 2, PROCEEDINGS: NETWORKING -CHALLENGES AND FRONTIERS, 2006, : 312 - +
  • [49] Efficient dynamic probabilistic packet marking for IP traceback
    Liu, JS
    Lee, ZJ
    Chung, YC
    ICON 2003: 11TH IEEE INTERNATIONAL CONFERENCE ON NETWORKS, 2003, : 475 - 480
  • [50] IP traceback with sparsely-tagged fragment marking scheme under massively multiple attack paths
    Kichang Kim
    Jeankyung Kim
    Jinsoo Hwang
    Cluster Computing, 2013, 16 : 229 - 239