Branch label based probabilistic packet marking for counteracting DDoS attacks

被引:0
|
作者
Ogawa, T [1 ]
Nakamura, F
Wakahara, Y
机构
[1] Hewlett Packard Japan Ltd, Tokyo 1688585, Japan
[2] Univ Tokyo, Grad Sch Frontier Sci, Tokyo 1130033, Japan
关键词
branch label; route label; probabilistic packet marking; IP traceback; IP spoofing; DDoS attacks;
D O I
暂无
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Effective counteraction to Distributed Denial-of-Services (DDoS) attacks is a pressing problem over the Internet. For this counteraction, it is considered important to locate the router interfaces closest to the attackers in order to effectively filter a great number of identification jammed packets with spoofed source addresses from widely distributed area. Edge sample (ES) based Probabilistic Packet Marking (PPM) is an encouraging method to cope with source IP spoofing, which usually accompanies DDoS attacks. But its fragmentation of path information leads to inefficiency in terms of necessary number of packets, path calculation time and identification accuracy. We propose Branch Label (BL) based PPM to solve the above inefficiency problem. In BL, a whole single path information is marked in a packet without fragmentation in contrast to ES based PPM. The whole path information in packets by the BL approach is expressed with branch information of each router interfaces. This brings the following three key advantages in the process of detecting the interfaces: quick increase in true-positives detected (efficiency), quick decrease in false-negatives detected (accuracy) and fast convergence (quickness).
引用
收藏
页码:1900 / 1909
页数:10
相关论文
共 50 条
  • [41] Adaptive Probabilistic Packet Marking Scheme for IP Traceback
    Fadlallah, Ahmad
    2014 WORLD CONGRESS ON COMPUTER APPLICATIONS AND INFORMATION SYSTEMS (WCCAIS), 2014,
  • [42] An efficient probabilistic packet marking scheme for IP traceback
    Duwairi, B
    Chakrabarti, A
    Manimaran, G
    NETWORKING 2004: NETWORKING TECHNOLOGIES, SERVICES, AND PROTOCOLS; PERFORMANCE OF COMPUTER AND COMMUNICATION NETWORKS; MOBILE AND WIRELESS COMMUNICATIONS, 2004, 3042 : 1263 - 1269
  • [43] Resistance Is Not Futile: Detecting DDoS Attacks without Packet Inspection
    Athreya, Arjun P.
    Wang, Xiao
    Kim, Yu Seung
    Tian, Yuan
    Tague, Patrick
    INFORMATION SECURITY APPLICATIONS, WISA 2013, 2014, 8267 : 174 - 188
  • [44] Markov chain modelling of the probabilistic packet marking algorithm
    Wong, Tsz-Yeung
    Lui, John Chi-Shing
    Wong, Man-Hon
    International Journal of Network Security, 2007, 5 (01) : 32 - 40
  • [45] Estimation of congestion price using probabilistic packet marking
    Adler, M
    Cai, JY
    Shapiro, JK
    Towsley, D
    IEEE INFOCOM 2003: THE CONFERENCE ON COMPUTER COMMUNICATIONS, VOLS 1-3, PROCEEDINGS, 2003, : 2068 - 2078
  • [46] On the performance of probabilistic packet marking for traceback in sensor networks
    Yang, Feng
    Zhou, Xuehai
    Zhang, Qjyuan
    Xie, Jing
    2008 5TH IEEE CONSUMER COMMUNICATIONS AND NETWORKING CONFERENCE, VOLS 1-3, 2008, : 682 - 686
  • [47] Extended probabilistic packet marking scheme for IP traceback
    Kwak, M
    Cho, DS
    SAM'03: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON SECURITY AND MANAGEMENT, VOLS 1 AND 2, 2003, : 521 - 524
  • [48] A precise termination condition of the probabilistic packet marking algorithm
    Wong, Tsz-Yeung
    Wong, Man-Hon
    John Lui, Chi-Shing
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2008, 5 (01) : 6 - 21
  • [49] Probabilistic packet marking with non-preemptive compensation
    Tseng, YK
    Chen, HH
    Hsieh, WS
    IEEE COMMUNICATIONS LETTERS, 2004, 8 (06) : 359 - 361
  • [50] Efficient dynamic probabilistic packet marking for IP traceback
    Liu, JS
    Lee, ZJ
    Chung, YC
    ICON 2003: 11TH IEEE INTERNATIONAL CONFERENCE ON NETWORKS, 2003, : 475 - 480