Novel hybrid schemes employing packet marking and logging for IP traceback

被引:50
|
作者
Al-Duwairi, B [1 ]
Govindarasu, M
机构
[1] Jordan Univ Sci & Technol, Fac Comp & Informat Technol, Dept Comp Engn, Irbid 22110, Jordan
[2] Iowa State Univ, Dept Elect & Comp Engn, Ames, IA 50011 USA
基金
美国国家科学基金会;
关键词
Internet security; DDoS attacks; IP traceback;
D O I
10.1109/TPDS.2006.63
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Tracing DoS attacks that employ source address spoofing is an important and challenging problem. Traditional traceback schemes provide spoofed packets traceback capability either by augmenting the packets with partial path information (i.e., packet marking) or by storing packet digests or signatures at intermediate routers (i.e., packet logging). Such approaches require either a large number of attack packets to be collected by the victim to infer the paths (packet marking) or a significant amount of resources to be reserved at intermediate routers (packet logging). We adopt a hybrid traceback approach in which packet marking and packet logging are integrated in a novel manner, so as to achieve the best of both worlds, that is, to achieve a small number of attack packets to conduct the traceback process and a small amount of resources to be allocated at intermediate routers for packet logging purposes. Based on this notion, two novel traceback schemes are presented. The first scheme, called Distributed Link-List Traceback (DLLT), is based on the idea of preserving the marking information at intermediate routers in such a way that it can be collected using a link list-based approach. The second scheme, called Probabilistic Pipelined Packet Marking (PPPM), employs the concept of a " pipeline" for propagating marking information from one marking router to another so that it eventually reaches the destination. We evaluate the effectiveness of the proposed schemes against various performance metrics through a combination of analytical and simulation studies. Our studies show that the proposed schemes offer a drastic reduction in the number of packets required to conduct the traceback process and a reasonable saving in the storage requirement.
引用
收藏
页码:403 / 418
页数:16
相关论文
共 50 条
  • [1] A hybrid scheme using packet marking and logging for IP traceback
    Malliga, S.
    Tamilarasi, A.
    [J]. INTERNATIONAL JOURNAL OF INTERNET PROTOCOL TECHNOLOGY, 2010, 5 (1-2) : 81 - 91
  • [2] Two novel packet marking schemes for IP traceback
    Hu, Hanping
    Wang, Yi
    Wang, Lingfei
    Guo, Wenxuan
    Ding, Mingyue
    [J]. AUTONOMIC AND TRUSTED COMPUTING, PROCEEDINGS, 2006, 4158 : 459 - 466
  • [3] IP traceback based on packet marking and logging
    Gong, C
    Sarac, K
    [J]. ICC 2005: IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, VOLS 1-5, 2005, : 1043 - 1047
  • [4] IP Traceback based on Deterministic Packet Marking and Logging
    Wang Xiao-jing
    Xiao You-lin
    [J]. 2009 INTERNATIONAL CONFERENCE ON SCALABLE COMPUTING AND COMMUNICATIONS & EIGHTH INTERNATIONAL CONFERENCE ON EMBEDDED COMPUTING, 2009, : 178 - +
  • [5] Modifications of Probabilistic packet marking schemes for IP traceback
    Lin, JH
    Xiao, W
    [J]. 8TH WORLD MULTI-CONFERENCE ON SYSTEMICS, CYBERNETICS AND INFORMATICS, VOL XI, PROCEEDINGS: CONTROL, COMMUNICATION AND NETWORK SYSTEMS, TECHNOLOGIES AND APPLICATIONS, 2004, : 89 - 91
  • [6] A novel packet marking scheme for IP traceback
    Al-Duwairi, B
    Manimaran, G
    [J]. TENTH INTERNATIONAL CONFERENCE ON PARALLEL AND DISTRIBUTED SYSTEMS, PROCEEDINGS, 2004, : 195 - 202
  • [7] A Precise and Practical IP Traceback Technique Based on Packet Marking and Logging
    Yan, Dong
    Wang, Yulong
    Su, Sen
    Yang, Fangchun
    [J]. JOURNAL OF INFORMATION SCIENCE AND ENGINEERING, 2012, 28 (03) : 453 - 470
  • [8] A Novel Deterministic Packet Marking Scheme for IP Traceback
    Qu Zhaoyang
    Huang Chunfeng
    [J]. 2008 WORKSHOP ON POWER ELECTRONICS AND INTELLIGENT TRANSPORTATION SYSTEM, PROCEEDINGS, 2008, : 38 - 41
  • [9] A comparative study on different probabilistic packet marking schemes for IP traceback
    Shioda, Shigeo
    Wang, Hui Jing
    [J]. TENCON 2006 - 2006 IEEE REGION 10 CONFERENCE, VOLS 1-4, 2006, : 1572 - +
  • [10] A packet marking scheme for IP traceback
    Qu, HP
    Su, PR
    Lin, DD
    Feng, DG
    [J]. NETWORKING - ICN 2005, PT 2, 2005, 3421 : 964 - 971