A more practical approach for single-packet IP traceback using packet logging and marking

被引:46
|
作者
Gong, Chao [1 ]
Sarac, Kamil [1 ]
机构
[1] Univ Texas Dallas, Dept Comp Sci, Richardson, TX 75080 USA
关键词
Internet security; denial-of-service (DoS) attack; IP traceback; packet logging; packet marking;
D O I
10.1109/TPDS.2007.70817
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Tracing IP packets back to their origins is an important step in defending the Internet against denial-of-service (DoS) attacks. Two kinds of IP traceback techniques have been proposed as packet marking and packet logging approaches. In packet marking, routers probabilistically write their identification information into the forwarded packets. This approach incurs little overhead but requires a large flow of packets to collect the complete path information. In packet logging, routers record the digests of the forwarded packets. This approach makes it possible to trace even a single packet and hence is considered more powerful. At routers forwarding a large volume of traffic, however, the high storage overhead and access time requirement for recording packet digests introduce practicality problems. In this paper, we present a novel scheme to improve the practicality of log-based IP traceback by reducing its overhead on routers. Our approach makes an intelligent use of packet marking to help improve the scalability of log-based IP traceback. We use mathematical analysis and simulations to evaluate our approach. Our evaluation results show that compared to the state-of-the-art log-based approach called Source Path Isolation Engine (SPIE), our approach maintains the ability to trace a single IP packet while reducing the storage overhead by half and the access time overhead by a factor of the number of neighboring routers.
引用
收藏
页码:1310 / 1324
页数:15
相关论文
共 50 条
  • [1] Single-packet IP traceback
    Snoeren, AC
    Partridge, C
    Sanchez, LA
    Jones, CE
    Tchakountio, F
    Schwartz, B
    Kent, ST
    Strayer, WT
    [J]. IEEE-ACM TRANSACTIONS ON NETWORKING, 2002, 10 (06) : 721 - 734
  • [2] Toward a practical packet marking approach for IP traceback
    Gong, Chao
    Sarac, Kamil
    [J]. International Journal of Network Security, 2009, 8 (03): : 271 - 281
  • [3] IP traceback based on packet marking and logging
    Gong, C
    Sarac, K
    [J]. ICC 2005: IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, VOLS 1-5, 2005, : 1043 - 1047
  • [4] A Precise and Practical IP Traceback Technique Based on Packet Marking and Logging
    Yan, Dong
    Wang, Yulong
    Su, Sen
    Yang, Fangchun
    [J]. JOURNAL OF INFORMATION SCIENCE AND ENGINEERING, 2012, 28 (03) : 453 - 470
  • [5] A hybrid scheme using packet marking and logging for IP traceback
    Malliga, S.
    Tamilarasi, A.
    [J]. INTERNATIONAL JOURNAL OF INTERNET PROTOCOL TECHNOLOGY, 2010, 5 (1-2) : 81 - 91
  • [6] IP Traceback based on Deterministic Packet Marking and Logging
    Wang Xiao-jing
    Xiao You-lin
    [J]. 2009 INTERNATIONAL CONFERENCE ON SCALABLE COMPUTING AND COMMUNICATIONS & EIGHTH INTERNATIONAL CONFERENCE ON EMBEDDED COMPUTING, 2009, : 178 - +
  • [7] A novel path-based approach for single-packet IP traceback
    Lu, Ning
    Wang, Yulong
    Su, Sen
    Yang, Fangchun
    [J]. SECURITY AND COMMUNICATION NETWORKS, 2014, 7 (02) : 309 - 321
  • [8] Novel hybrid schemes employing packet marking and logging for IP traceback
    Al-Duwairi, B
    Govindarasu, M
    [J]. IEEE TRANSACTIONS ON PARALLEL AND DISTRIBUTED SYSTEMS, 2006, 17 (05) : 403 - 418
  • [9] A packet marking scheme for IP traceback
    Qu, HP
    Su, PR
    Lin, DD
    Feng, DG
    [J]. NETWORKING - ICN 2005, PT 2, 2005, 3421 : 964 - 971
  • [10] Hybrid Single-Packet IP Traceback with Low Storage and High Accuracy
    Yang, Ming Hour
    [J]. SCIENTIFIC WORLD JOURNAL, 2014,