Branch label based probabilistic packet marking for IP traceback

被引:0
|
作者
Ogawa, T [1 ]
Nakamura, F [1 ]
Wakahara, Y [1 ]
机构
[1] Univ Tokyo, Grad Sch Frontier Sci, Bunkyo Ku, Tokyo 1138658, Japan
关键词
Branch Label; Route Label; probabilistic packet marking; IP traceback; IP spoofing; DDoS attacks;
D O I
暂无
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
Distributed Denial-of-Services (DDoS) attacks have been one of the most serious security issues. DDoS attacks disable legitimate services on victim hosts by flooding packet flows to the hosts from a lot of different compromised hosts. It is considered the most effective mitigation to filter the attacking packet flows at the router interfaces closest to the attackers. Precise identification of these interfaces is a key point. Edge Sample (ES) based Probabilistic Packet Marking (PPM) is an encouraging method to cope with source IP spoofing, a popular identification jamming, which usually accompany DDoS attacks. But its fragmentation of path information leads to inefficiency in terms of necessary number of packets, path calculation time and identification accuracy. We propose Branch Label (BL) based PPM to solve the above inefficiency problem. In BL, a single path information is marked in a packet without fragmentation in contrast to ES based PPM. The whole path information in packets by the BL approach is expressed with branch information of each router interfaces. This brings the following three key advantages in the process of detecting the interfaces: quick increase in true-positives detected (efficiency), quick decrease in false-negatives detected (accuracy) and fast convergence (quickness).
引用
收藏
页码:467 / 474
页数:8
相关论文
共 50 条
  • [31] A Fast Deterministic Packet Marking Scheme for IP Traceback
    Wang Xiao-jing
    Hu Chang-zhen
    Hu He
    MINES 2009: FIRST INTERNATIONAL CONFERENCE ON MULTIMEDIA INFORMATION NETWORKING AND SECURITY, VOL 2, PROCEEDINGS, 2009, : 526 - 529
  • [32] Toward a practical packet marking approach for IP traceback
    Gong, Chao
    Sarac, Kamil
    International Journal of Network Security, 2009, 8 (03): : 271 - 281
  • [33] Advanced packet marking mechanism with pushback for IP traceback
    Lee, HW
    APPLIED CRYPTOGRAPHY AND NETWORK SECURITY, PROCEEDINGS, 2004, 3089 : 426 - 438
  • [34] Survey on Packet Marking Fields and Information for IP Traceback
    Vasseur, Marion
    Khatoun, Rida
    Serhrouchni, Ahmed
    2015 INTERNATIONAL CONFERENCE ON PROTOCOL ENGINEERING (ICPE) AND INTERNATIONAL CONFERENCE ON NEW TECHNOLOGIES OF DISTRIBUTED SYSTEMS (NTDS), 2015,
  • [35] Towards an adaptive packet marking scheme for IP traceback
    Yan, Ping
    Lee, Moon Chuen
    E-BUSINESS AND TELECOMMUNICATION NETWORKS, 2006, : 141 - +
  • [36] Enhanced and authenticated deterministic packet marking for IP traceback
    Peng, Dan
    Shi, Zhicai
    Tao, Longming
    Ma, Wu
    ADVANCED PARALLEL PROCESSING TECHNOLOGIES, PROCEEDINGS, 2007, 4847 : 508 - 517
  • [37] Two novel packet marking schemes for IP traceback
    Hu, Hanping
    Wang, Yi
    Wang, Lingfei
    Guo, Wenxuan
    Ding, Mingyue
    AUTONOMIC AND TRUSTED COMPUTING, PROCEEDINGS, 2006, 4158 : 459 - 466
  • [38] Accommodating fragmentation in deterministic packet marking for IP traceback
    Belenky, A
    Ansari, N
    GLOBECOM'03: IEEE GLOBAL TELECOMMUNICATIONS CONFERENCE, VOLS 1-7, 2003, : 1374 - 1378
  • [39] Survey on Packet Marking Fields and Information for IP Traceback
    Vasseur, Marion
    Chen, Xiuzhen
    Khatoun, Rida
    Serhrouchni, Ahmed
    2015 INTERNATIONAL CONFERENCE ON CYBER SECURITY OF SMART CITIES, INDUSTRIAL CONTROL AND COMMUNICATIONS (SSIC), 2015,
  • [40] Deterministic Packet Marking with Link Signatures for IP traceback
    Shi Yi
    Yang Xinyu
    Li Ning
    Qi Yong
    INFORMATION SECURITY AND CRYPTOLOGY, PROCEEDINGS, 2006, 4318 : 144 - +