DocumentCode
1714030
Title
A more accurate completion condition for attack-graph reconstruction in Probabilistic Packet Marking algorithm
Author
Saurabh, Samant ; Sairam, Ashok Singh
Author_Institution
Department of Computer Science, Indian Institute of Technology, Patna 800013, India
fYear
2013
Firstpage
1
Lastpage
5
Abstract
Probabilistic Packet Marking (PPM) is one of the most promising scheme for IP Traceback in case of DDoS attack. PPM reconstructs the attack graph in order to trace back to the attackers´ network. Finding precise completion condition (i.e. number of packets required to reconstruct the attack graph) is very important. Without correct completion condition, victim might reconstruct a wrong or incomplete attack-graph. On the other extreme if it waits too long (much more than required) to collect marked packets, the real attacker would get ample time to destroy logs, traces and records and easily evade detection. Our work gives a precise completion condition for PPM that guarantees that when attack graph is reconstructed, it is correct with high probability. The main contribution of our work is - it increases the reliability and correctness of PPM algorithm and improves the chances of exact attack origin detection instead of just tracing to the attackers´ network. Our results show that relying on upper bound of expected number of packets equation which is implicitly accepted as the completion condition for PPM is not very accurate as it reconstructs wrong attack graph for even upto 37% of cases whereas our algorithm has error rate of just around 7% with minimal increase in number of required packets.
Keywords
Computer crime; IP networks; Probabilistic logic; Reconstruction algorithms; Reliability; Standards; Upper bound;
fLanguage
English
Publisher
ieee
Conference_Titel
Communications (NCC), 2013 National Conference on
Conference_Location
New Delhi, India
Print_ISBN
978-1-4673-5950-4
Electronic_ISBN
978-1-4673-5951-1
Type
conf
DOI
10.1109/NCC.2013.6488043
Filename
6488043
Link To Document