Branch label based probabilistic packet marking for counteracting DDoS attacks

被引:0
|
作者
Ogawa, T [1 ]
Nakamura, F
Wakahara, Y
机构
[1] Hewlett Packard Japan Ltd, Tokyo 1688585, Japan
[2] Univ Tokyo, Grad Sch Frontier Sci, Tokyo 1130033, Japan
关键词
branch label; route label; probabilistic packet marking; IP traceback; IP spoofing; DDoS attacks;
D O I
暂无
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Effective counteraction to Distributed Denial-of-Services (DDoS) attacks is a pressing problem over the Internet. For this counteraction, it is considered important to locate the router interfaces closest to the attackers in order to effectively filter a great number of identification jammed packets with spoofed source addresses from widely distributed area. Edge sample (ES) based Probabilistic Packet Marking (PPM) is an encouraging method to cope with source IP spoofing, which usually accompanies DDoS attacks. But its fragmentation of path information leads to inefficiency in terms of necessary number of packets, path calculation time and identification accuracy. We propose Branch Label (BL) based PPM to solve the above inefficiency problem. In BL, a whole single path information is marked in a packet without fragmentation in contrast to ES based PPM. The whole path information in packets by the BL approach is expressed with branch information of each router interfaces. This brings the following three key advantages in the process of detecting the interfaces: quick increase in true-positives detected (efficiency), quick decrease in false-negatives detected (accuracy) and fast convergence (quickness).
引用
收藏
页码:1900 / 1909
页数:10
相关论文
共 50 条
  • [1] Branch label based probabilistic packet marking for IP traceback
    Ogawa, T
    Nakamura, F
    Wakahara, Y
    ICON 2003: 11TH IEEE INTERNATIONAL CONFERENCE ON NETWORKS, 2003, : 467 - 474
  • [2] The packet marking and the filtering protocol to counter against the DDoS attacks
    Park, J
    Choi, JH
    Seo, DW
    PARALLEL AND DISTRIBUTED COMPUTING: APPLICATIONS AND TECHNOLOGIES, PROCEEDINGS, 2004, 3320 : 624 - 627
  • [3] Resisting network DDoS attacks by packet asymmetry path marking
    Jin, Guang
    Yang, Jiangang
    Wei, Wei
    Dong, Yabo
    2007 SECOND INTERNATIONAL CONFERENCE IN COMMUNICATIONS AND NETWORKING IN CHINA, VOLS 1 AND 2, 2007, : 363 - 367
  • [4] On the (in)effectiveness of probabilistic marking for IP traceback under DDoS attacks
    Paruchuri, Vamsi
    Durresi, Arjan
    Jain, Raj
    GLOBECOM 2007: 2007 IEEE GLOBAL TELECOMMUNICATIONS CONFERENCE, VOLS 1-11, 2007, : 1965 - +
  • [5] A Packet Marking Approach To Protect Cloud Environment Against DDoS Attacks
    Anitha, E.
    Malliga, S.
    2013 INTERNATIONAL CONFERENCE ON INFORMATION COMMUNICATION AND EMBEDDED SYSTEMS (ICICES), 2013, : 367 - 370
  • [6] CERTAIN IMPROVEMENTS TO LOCATION AIDED PACKET MARKING AND DDOS ATTACKS IN INTERNET
    Satheesh, N.
    Sudha, D.
    Suganthi, D.
    Sudhakar, S.
    Dhanaraj, S.
    Sriram, V. P.
    Priya, V
    JOURNAL OF ENGINEERING SCIENCE AND TECHNOLOGY, 2020, 15 (01): : 94 - 107
  • [7] An effective defense mechanism for DDoS attack via traceback and probabilistic packet marking
    College of Mathematics and Information Science, Zhengzhou University of Light Industry, No. 5, Dongfeng Road, Zhengzhou, China
    不详
    ICIC Express Lett Part B Appl., 11 (2977-2982):
  • [8] TAP: A Traffic-Aware Probabilistic Packet Marking for Collaborative DDoS Mitigation
    Liu, Mingxing
    Liu, Ying
    Xu, Ke
    He, Lin
    Wang, Xiaoliang
    Guo, Yangfei
    Jiang, Weiyu
    2021 17TH INTERNATIONAL CONFERENCE ON MOBILITY, SENSING AND NETWORKING (MSN 2021), 2021, : 470 - 478
  • [9] Dynamic Probabilistic Packet Marking Based On PPM
    Bo, Feng
    Fan, Guo
    Min, Yu
    PROCEEDINGS OF THE 2009 SECOND PACIFIC-ASIA CONFERENCE ON WEB MINING AND WEB-BASED APPLICATION, 2009, : 289 - 292
  • [10] Defending DDoS attacks using network traffic analysis and probabilistic packet drop
    Seo, J
    Lee, C
    Moon, J
    GRID AND COOPERATIVE COMPUTING GCC 2004 WORKSHOPS, PROCEEDINGS, 2004, 3252 : 390 - 397