Branch label based probabilistic packet marking for IP traceback

被引:0
|
作者
Ogawa, T [1 ]
Nakamura, F [1 ]
Wakahara, Y [1 ]
机构
[1] Univ Tokyo, Grad Sch Frontier Sci, Bunkyo Ku, Tokyo 1138658, Japan
关键词
Branch Label; Route Label; probabilistic packet marking; IP traceback; IP spoofing; DDoS attacks;
D O I
暂无
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
Distributed Denial-of-Services (DDoS) attacks have been one of the most serious security issues. DDoS attacks disable legitimate services on victim hosts by flooding packet flows to the hosts from a lot of different compromised hosts. It is considered the most effective mitigation to filter the attacking packet flows at the router interfaces closest to the attackers. Precise identification of these interfaces is a key point. Edge Sample (ES) based Probabilistic Packet Marking (PPM) is an encouraging method to cope with source IP spoofing, a popular identification jamming, which usually accompany DDoS attacks. But its fragmentation of path information leads to inefficiency in terms of necessary number of packets, path calculation time and identification accuracy. We propose Branch Label (BL) based PPM to solve the above inefficiency problem. In BL, a single path information is marked in a packet without fragmentation in contrast to ES based PPM. The whole path information in packets by the BL approach is expressed with branch information of each router interfaces. This brings the following three key advantages in the process of detecting the interfaces: quick increase in true-positives detected (efficiency), quick decrease in false-negatives detected (accuracy) and fast convergence (quickness).
引用
收藏
页码:467 / 474
页数:8
相关论文
共 50 条
  • [21] Packet Marking With Distance Based Probabilities for IP Traceback
    Akyuz, Turker
    Sogukpinar, Ibrahim
    2009 FIRST INTERNATIONAL CONFERENCE ON NETWORKS & COMMUNICATIONS (NETCOM 2009), 2009, : 433 - 438
  • [22] Branch label based probabilistic packet marking for counteracting DDoS attacks
    Ogawa, T
    Nakamura, F
    Wakahara, Y
    IEICE TRANSACTIONS ON COMMUNICATIONS, 2004, E87B (07) : 1900 - 1909
  • [23] On packet marking and Markov modeling for IP Traceback: A deep probabilistic and stochastic analysis
    Fazio, Peppino
    Tropea, Mauro
    Voznak, Miroslav
    De Rango, Floriano
    COMPUTER NETWORKS, 2020, 182
  • [24] On the effectiveness of probabilistic packet marking for IP traceback under denial of service attack
    Park, K
    Lee, H
    IEEE INFOCOM 2001: THE CONFERENCE ON COMPUTER COMMUNICATIONS, VOLS 1-3, PROCEEDINGS: TWENTY YEARS INTO THE COMMUNICATIONS ODYSSEY, 2001, : 338 - 347
  • [25] An implementation of IP traceback in IPv6 using probabilistic packet marking
    Albright, E
    Dang, XH
    ICOMP '05: PROCEEDINGS OF THE 2005 INTERNATIONAL CONFERENCE ON INTERNET COMPUTING, 2005, : 416 - 421
  • [26] Deterministic packet marking based on redundant decomposition for IP traceback
    Jin, Guang
    Yang, Jiangang
    IEEE COMMUNICATIONS LETTERS, 2006, 10 (03) : 204 - 206
  • [27] A novel packet marking scheme for IP traceback
    Al-Duwairi, B
    Manimaran, G
    TENTH INTERNATIONAL CONFERENCE ON PARALLEL AND DISTRIBUTED SYSTEMS, PROCEEDINGS, 2004, : 195 - 202
  • [28] Probabilistic Flow Marking for IP Traceback (PFM)
    Aghaei-Foroushani, Vahid
    Zincir-Heywood, A. Nur
    2015 7TH INTERNATIONAL WORKSHOP ON RELIABLE NETWORKS DESIGN AND MODELING (RNDM) PROCE4EDINGS, 2015, : 229 - 236
  • [29] A Precise and Practical IP Traceback Technique Based on Packet Marking and Logging
    Yan, Dong
    Wang, Yulong
    Su, Sen
    Yang, Fangchun
    JOURNAL OF INFORMATION SCIENCE AND ENGINEERING, 2012, 28 (03) : 453 - 470
  • [30] A Novel Deterministic Packet Marking Scheme for IP Traceback
    Qu Zhaoyang
    Huang Chunfeng
    2008 WORKSHOP ON POWER ELECTRONICS AND INTELLIGENT TRANSPORTATION SYSTEM, PROCEEDINGS, 2008, : 38 - 41