Branch label based probabilistic packet marking for IP traceback

被引:0
|
作者
Ogawa, T [1 ]
Nakamura, F [1 ]
Wakahara, Y [1 ]
机构
[1] Univ Tokyo, Grad Sch Frontier Sci, Bunkyo Ku, Tokyo 1138658, Japan
关键词
Branch Label; Route Label; probabilistic packet marking; IP traceback; IP spoofing; DDoS attacks;
D O I
暂无
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
Distributed Denial-of-Services (DDoS) attacks have been one of the most serious security issues. DDoS attacks disable legitimate services on victim hosts by flooding packet flows to the hosts from a lot of different compromised hosts. It is considered the most effective mitigation to filter the attacking packet flows at the router interfaces closest to the attackers. Precise identification of these interfaces is a key point. Edge Sample (ES) based Probabilistic Packet Marking (PPM) is an encouraging method to cope with source IP spoofing, a popular identification jamming, which usually accompany DDoS attacks. But its fragmentation of path information leads to inefficiency in terms of necessary number of packets, path calculation time and identification accuracy. We propose Branch Label (BL) based PPM to solve the above inefficiency problem. In BL, a single path information is marked in a packet without fragmentation in contrast to ES based PPM. The whole path information in packets by the BL approach is expressed with branch information of each router interfaces. This brings the following three key advantages in the process of detecting the interfaces: quick increase in true-positives detected (efficiency), quick decrease in false-negatives detected (accuracy) and fast convergence (quickness).
引用
收藏
页码:467 / 474
页数:8
相关论文
共 50 条
  • [41] On the performance of probabilistic packet marking for traceback in sensor networks
    Yang, Feng
    Zhou, Xuehai
    Zhang, Qjyuan
    Xie, Jing
    2008 5TH IEEE CONSUMER COMMUNICATIONS AND NETWORKING CONFERENCE, VOLS 1-3, 2008, : 682 - 686
  • [42] DDPM:Dynamic deterministic packet marking for IP traceback
    Shokri, Reza
    Varshovi, Ali
    Mohammadi, Hossein
    Yazdani, Nasser
    Sadeghian, Babak
    ICON: 2006 IEEE INTERNATIONAL CONFERENCE ON NETWORKS, VOLS 1 AND 2, PROCEEDINGS: NETWORKING -CHALLENGES AND FRONTIERS, 2006, : 312 - +
  • [43] IP traceback by packet marking method with bloom filters
    Takurou, Hosoi
    Matsuura, Kanta
    Mai, Hideki
    41ST ANNUAL IEEE INTERNATIONAL CARNAHAN CONFERENCE ON SECURITY TECHNOLOGY, PROCEEDINGS, 2007, : 255 - +
  • [44] IP Traceback through modified Probabilistic Packet Marking algorithm using Chinese Remainder Theorem
    Bhavani, Y.
    Janaki, V.
    Sridevi, R.
    AIN SHAMS ENGINEERING JOURNAL, 2015, 6 (02) : 715 - 722
  • [45] Fast and secure probabilistic marking technology for IP traceback
    Tian, Hongcheng
    Bi, Jun
    Jiang, Xiaoke
    Wang, Dekai
    Zhang, Wei
    Qinghua Daxue Xuebao/Journal of Tsinghua University, 2011, 51 (04): : 542 - 547
  • [46] An intelligent approach of packet marking at edge router for IP traceback
    Kim, DS
    Hong, CS
    Xiang, Y
    KNOWLEDGE-BASED INTELLIGENT INFORMATION AND ENGINEERING SYSTEMS, PT 3, PROCEEDINGS, 2005, 3683 : 303 - 309
  • [47] Robust and Scalable Deterministic Packet Marking Scheme for IP Traceback
    Lin, Iven
    Lee, Tsern-Huei
    GLOBECOM 2006 - 2006 IEEE GLOBAL TELECOMMUNICATIONS CONFERENCE, 2006,
  • [48] LPM: A lightweight authenticated packet marking approach for IP traceback
    Patel, Hasmukh
    Jinwala, Devesh C.
    COMPUTER NETWORKS, 2018, 140 : 41 - 50
  • [50] Across-domain deterministic packet marking for IP traceback
    Jin, Guang
    Yang, Jiangang
    Wei, Wei
    Dong, Yabo
    2007 SECOND INTERNATIONAL CONFERENCE IN COMMUNICATIONS AND NETWORKING IN CHINA, VOLS 1 AND 2, 2007, : 353 - 357