• DocumentCode
    160628
  • Title

    IP Spoofing Detection Using Modified Hop Count

  • Author

    Mukaddam, Ayman ; Elhajj, I. ; Kayssi, Ayman ; Chehab, Ali

  • Author_Institution
    Electr. & Comput. Eng. Dept., American Univ. of Beirut, Beirut, Lebanon
  • fYear
    2014
  • fDate
    13-16 May 2014
  • Firstpage
    512
  • Lastpage
    516
  • Abstract
    With the global widespread usage of the Internet, more and more cyber-attacks are being performed. Many of these attacks utilize IP address spoofing. This paper describes IP spoofing attacks and the proposed methods currently available to detect or prevent them. In addition, it presents a statistical analysis of the Hop Count parameter used in our proposed IP spoofing detection algorithm. We propose an algorithm, inspired by the Hop Count Filtering (HCF) technique, that changes the learning phase of HCF to include all the possible available Hop Count values. Compared to the original HCF method and its variants, our proposed method increases the true positive rate by at least 9% and consequently increases the overall accuracy of an intrusion detection system by at least 9%. Our proposed method performs in general better than HCF method and its variants.
  • Keywords
    IP networks; Internet; computer network security; statistical analysis; HCF learning phase; IP address spoofing utilization; IP spoofing attacks; IP spoofing detection; Internet; hop count filtering technique; modified hop count parameter; statistical analysis; Computer crime; Filtering; IP networks; Internet; Routing protocols; Testing; IP spoofing; hop count; hop count filtering; statistical analysis;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Advanced Information Networking and Applications (AINA), 2014 IEEE 28th International Conference on
  • Conference_Location
    Victoria, BC
  • ISSN
    1550-445X
  • Print_ISBN
    978-1-4799-3629-8
  • Type

    conf

  • DOI
    10.1109/AINA.2014.62
  • Filename
    6838707