DocumentCode
1760812
Title
Passive IP Traceback: Disclosing the Locations of IP Spoofers From Path Backscatter
Author
Guang Yao ; Jun Bi ; Vasilakos, Athanasios V.
Author_Institution
Dept. of Comput. ScienceInstitute for Network Sci. & Cyberspace, Tsinghua Univ., Beijing, China
Volume
10
Issue
3
fYear
2015
fDate
42064
Firstpage
471
Lastpage
484
Abstract
It is long known attackers may use forged source IP address to conceal their real locations. To capture the spoofers, a number of IP traceback mechanisms have been proposed. However, due to the challenges of deployment, there has been not a widely adopted IP traceback solution, at least at the Internet level. As a result, the mist on the locations of spoofers has never been dissipated till now. This paper proposes passive IP traceback (PIT) that bypasses the deployment difficulties of IP traceback techniques. PIT investigates Internet Control Message Protocol error messages (named path backscatter) triggered by spoofing traffic, and tracks the spoofers based on public available information (e.g., topology). In this way, PIT can find the spoofers without any deployment requirement. This paper illustrates the causes, collection, and the statistical results on path backscatter, demonstrates the processes and effectiveness of PIT, and shows the captured locations of spoofers through applying PIT on the path backscatter data set. These results can help further reveal IP spoofing, which has been studied for long but never well understood. Though PIT cannot work in all the spoofing attacks, it may be the most useful mechanism to trace spoofers before an Internet-level traceback system has been deployed in real.
Keywords
IP networks; Internet; computer network security; protocols; IP traceback mechanisms; IP traceback solution; IP traceback techniques; Internet control message protocol error messages; Internet level; PIT; forged source IP address; passive IP traceback; path backscatter; public available information; spoofing attacks; Backscatter; Computer crime; IP networks; Internet; Logic gates; Telescopes; Topology; Computer network management; Computer network management,; IP traceback; computer network security; denial of service (DoS);
fLanguage
English
Journal_Title
Information Forensics and Security, IEEE Transactions on
Publisher
ieee
ISSN
1556-6013
Type
jour
DOI
10.1109/TIFS.2014.2381873
Filename
6987335
Link To Document