Branch label based probabilistic packet marking for IP traceback

被引:0
|
作者
Ogawa, T [1 ]
Nakamura, F [1 ]
Wakahara, Y [1 ]
机构
[1] Univ Tokyo, Grad Sch Frontier Sci, Bunkyo Ku, Tokyo 1138658, Japan
关键词
Branch Label; Route Label; probabilistic packet marking; IP traceback; IP spoofing; DDoS attacks;
D O I
暂无
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
Distributed Denial-of-Services (DDoS) attacks have been one of the most serious security issues. DDoS attacks disable legitimate services on victim hosts by flooding packet flows to the hosts from a lot of different compromised hosts. It is considered the most effective mitigation to filter the attacking packet flows at the router interfaces closest to the attackers. Precise identification of these interfaces is a key point. Edge Sample (ES) based Probabilistic Packet Marking (PPM) is an encouraging method to cope with source IP spoofing, a popular identification jamming, which usually accompany DDoS attacks. But its fragmentation of path information leads to inefficiency in terms of necessary number of packets, path calculation time and identification accuracy. We propose Branch Label (BL) based PPM to solve the above inefficiency problem. In BL, a single path information is marked in a packet without fragmentation in contrast to ES based PPM. The whole path information in packets by the BL approach is expressed with branch information of each router interfaces. This brings the following three key advantages in the process of detecting the interfaces: quick increase in true-positives detected (efficiency), quick decrease in false-negatives detected (accuracy) and fast convergence (quickness).
引用
收藏
页码:467 / 474
页数:8
相关论文
共 50 条
  • [1] Enhanced Probabilistic packet marking for IP traceback
    Gao, ZQ
    Ansari, N
    [J]. GLOBECOM '05: IEEE GLOBAL TELECOMMUNICATIONS CONFERENCE, VOLS 1-6: DISCOVERY PAST AND FUTURE, 2005, : 1676 - 1680
  • [2] A traceback approach with probabilistic packet marking IP based on cooperations
    [J]. Yan, D. (yandong200@gmail.com), 1600, Beijing University of Posts and Telecommunications (35):
  • [3] Extended probabilistic packet marking scheme for IP traceback
    Kwak, M
    Cho, DS
    [J]. SAM'03: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON SECURITY AND MANAGEMENT, VOLS 1 AND 2, 2003, : 521 - 524
  • [4] Modifications of Probabilistic packet marking schemes for IP traceback
    Lin, JH
    Xiao, W
    [J]. 8TH WORLD MULTI-CONFERENCE ON SYSTEMICS, CYBERNETICS AND INFORMATICS, VOL XI, PROCEEDINGS: CONTROL, COMMUNICATION AND NETWORK SYSTEMS, TECHNOLOGIES AND APPLICATIONS, 2004, : 89 - 91
  • [5] Dynamic probabilistic packet marking for efficient IP traceback
    Liu, Jenshiuh
    Lee, Zhi-Jian
    Chung, Yeh-Ching
    [J]. COMPUTER NETWORKS, 2007, 51 (03) : 866 - 882
  • [6] Adaptive Probabilistic Packet Marking Scheme for IP Traceback
    Fadlallah, Ahmad
    [J]. 2014 WORLD CONGRESS ON COMPUTER APPLICATIONS AND INFORMATION SYSTEMS (WCCAIS), 2014,
  • [7] An efficient probabilistic packet marking scheme for IP traceback
    Duwairi, B
    Chakrabarti, A
    Manimaran, G
    [J]. NETWORKING 2004: NETWORKING TECHNOLOGIES, SERVICES, AND PROTOCOLS; PERFORMANCE OF COMPUTER AND COMMUNICATION NETWORKS; MOBILE AND WIRELESS COMMUNICATIONS, 2004, 3042 : 1263 - 1269
  • [8] Efficient dynamic probabilistic packet marking for IP traceback
    Liu, JS
    Lee, ZJ
    Chung, YC
    [J]. ICON 2003: 11TH IEEE INTERNATIONAL CONFERENCE ON NETWORKS, 2003, : 475 - 480
  • [9] Trade-offs in probabilistic packet marking for IP traceback
    Adler, M
    [J]. JOURNAL OF THE ACM, 2005, 52 (02) : 217 - 244
  • [10] Probabilistic packet marking for large-scale IP traceback
    Goodrich, Michael T.
    [J]. IEEE-ACM TRANSACTIONS ON NETWORKING, 2008, 16 (01) : 15 - 24