IP Traceback based on Deterministic Packet Marking and Logging

被引:0
|
作者
Wang Xiao-jing [1 ,2 ]
Xiao You-lin [3 ]
机构
[1] Beijing Inst Technol, Lab Comp Network Def Technol, Beijing 100081, Peoples R China
[2] Xain Polit Inst, Xian, Peoples R China
[3] Beijing Mil Representat, Gen Armament Dept, Beijing, Peoples R China
关键词
network security; distributed denial of service (DDoS); IP traceback; deterministic packet marking (DPM); packet logging;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
IP traceback mechanisms are a critical part of the defense against IP spoofing and DoS attacks. Currently proposed traceback mechanisms are inadequate to address the traceback problem for the following reasons: they lack incentives for ISPs to deploy IP traceback in their networks; they do not scale to large scale distributed DoS attacks. In this paper, a novel IP traceback approach based on packet logging and deterministic packet marking (LDPM) is proposed, that significantly improves IP traceback in several aspects: (1) LDPM is built on a distributed hierarchical IP traceback system, and is simple to deploy. (2) LDPM uses a new IP header encoding scheme to store the complete identification information of a router into a single packet, thus it can protect the privacy of network topology and victims can identify attack ingress router with one packet. It also can cope with large distributed attacks with thousands of attackers. (3) LDPM can manipulate the marking information at the edge ingress routers. Therefore, as a value-added services, ISPs can provide traceback business to their customers. Compared with previous traceback schemes, LDPM improves the performance and practicability of IF traceback.
引用
收藏
页码:178 / +
页数:2
相关论文
共 50 条
  • [21] A more practical approach for single-packet IP traceback using packet logging and marking
    Gong, Chao
    Sarac, Kamil
    IEEE TRANSACTIONS ON PARALLEL AND DISTRIBUTED SYSTEMS, 2008, 19 (10) : 1310 - 1324
  • [22] Packet Marking With Distance Based Probabilities for IP Traceback
    Akyuz, Turker
    Sogukpinar, Ibrahim
    2009 FIRST INTERNATIONAL CONFERENCE ON NETWORKS & COMMUNICATIONS (NETCOM 2009), 2009, : 433 - 438
  • [23] Deterministic and Authenticated Flow Marking for IP Traceback
    Foroushani, Vahid Aghaei
    Zincir-Heywood, A. Nur
    2013 IEEE 27TH INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION NETWORKING AND APPLICATIONS (AINA), 2013, : 397 - 404
  • [24] Branch label based probabilistic packet marking for IP traceback
    Ogawa, T
    Nakamura, F
    Wakahara, Y
    ICON 2003: 11TH IEEE INTERNATIONAL CONFERENCE ON NETWORKS, 2003, : 467 - 474
  • [25] A novel packet marking scheme for IP traceback
    Al-Duwairi, B
    Manimaran, G
    TENTH INTERNATIONAL CONFERENCE ON PARALLEL AND DISTRIBUTED SYSTEMS, PROCEEDINGS, 2004, : 195 - 202
  • [26] Enhanced Probabilistic packet marking for IP traceback
    Gao, ZQ
    Ansari, N
    GLOBECOM '05: IEEE GLOBAL TELECOMMUNICATIONS CONFERENCE, VOLS 1-6: DISCOVERY PAST AND FUTURE, 2005, : 1676 - 1680
  • [27] Flexible Deterministic Packet Marking: An IP Traceback System to Find the Real Source of Attacks
    Xiang, Yang
    Zhou, Wanlei
    Guo, Minyi
    IEEE TRANSACTIONS ON PARALLEL AND DISTRIBUTED SYSTEMS, 2009, 20 (04) : 567 - 580
  • [28] A traceback approach with probabilistic packet marking IP based on cooperations
    Yan, D. (yandong200@gmail.com), 1600, Beijing University of Posts and Telecommunications (35):
  • [29] Traceback in wireless sensor networks with packet marking and logging
    Jun Xu
    Xuehai Zhou
    Feng Yang
    Frontiers of Computer Science in China, 2011, 5 : 308 - 315
  • [30] Traceback in wireless sensor networks with packet marking and logging
    Xu, Jun
    Zhou, Xuehai
    Yang, Feng
    FRONTIERS OF COMPUTER SCIENCE IN CHINA, 2011, 5 (03): : 308 - 315