DocumentCode :
2128471
Title :
Tracing multiple attackers with deterministic packet marking (DPM)
Author :
Belenky, Andrey ; Ansari, Nitwan
Author_Institution :
Dept. of ECE, NJIT, Newark, NJ, USA
Volume :
1
fYear :
2003
fDate :
28-30 Aug. 2003
Firstpage :
49
Abstract :
The rising threat of cyber attacks, especially distributed denial-of-service (DDoS), and makes the IP traceback problem very relevant to today´s Internet security. IP traceback is one of the security problems associated with identifying the source of the attack packets. This work presents a novel approach to IP traceback - deterministic packet marking (DPM). The proposed approach is scalable, simple to implement, and introduces no bandwidth and practically no processing overhead on the network equipment It is capable of tracing thousands of simultaneous attackers during DDoS attack. All of the processing is done at the victim. The traceback process can be performed post-mortem, which allows for tracing the attacks that may not have been noticed initially. The involvement of the Internet service providers (ISP) is very limited, and changes to the infrastructure and operation required to deploy DPM are minimal. DPM performs the traceback without revealing the internal topology of the provider´s network, which is a desirable quality of a traceback scheme.
Keywords :
Internet; telecommunication security; telecommunication services; IP traceback; ISP; Internet security; Internet service providers; deterministic packet marking; distributed denial-of-service; multiple attacker tracing; Bandwidth; Computer crime; Encoding; Gold; IP networks; Laboratories; Large-scale systems; Network topology; Radio frequency; Web and internet services;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Communications, Computers and signal Processing, 2003. PACRIM. 2003 IEEE Pacific Rim Conference on
Print_ISBN :
0-7803-7978-0
Type :
conf
DOI :
10.1109/PACRIM.2003.1235716
Filename :
1235716
Link To Document :
بازگشت