DocumentCode
2372762
Title
Analysis of adjusted probabilistic packet marking
Author
Rizvi, Bilal ; Fernandez-Gaucherand, E.
Author_Institution
Dept. of Electr. & Comput. Eng. & Comput. Sci., Cincinnati Univ., OH, USA
fYear
2003
fDate
1-3 Oct. 2003
Firstpage
9
Lastpage
13
Abstract
Probabilistic packet marking (PPM) has been proposed for the identification of the source of a denial of service (DoS) attack (Savage, S. et al., Proc. ACM SIGCOM, p.295-305, 2000). PPM is based on marking packets with a fixed probability by all routers. However, using a fixed marking probability allows a large number of packets to reach the victim unmarked, which can be spoofed to impede traceback. Also, using a fixed marking probability, the victim receives fewer marked packets from routers further away from the victim, which increases the computational time needed for traceback. Hence, we study the adjusted probabilistic packet marking (APPM) scheme (Teo Peng et al., Proc. Networking, 2002), where variable marking probability is used so that the victim receives packets from all routers with equal probability. However, using the analysis similar to that of Kihomg Park and Heejo Lee (see Proc. IEEE INFOCOM, 2001) we show that APPM is also subject to spoofing of the marking field for smaller path lengths. A modified version of APPM is proposed that reduces unmarked packets reaching the victim and the computational time needed for traceback.
Keywords
Internet; computer crime; probability; telecommunication security; DoS attack; Internet; adjusted probabilistic packet marking; computational time; denial of service attack; traceback; variable marking probability; Computer crime; Computer science; Impedance; Web and internet services;
fLanguage
English
Publisher
ieee
Conference_Titel
IP Operations & Management, 2003. (IPOM 2003). 3rd IEEE Workshop on
Print_ISBN
0-7803-8199-8
Type
conf
DOI
10.1109/IPOM.2003.1251218
Filename
1251218
Link To Document