• DocumentCode
    2510230
  • Title

    IP Traceback Based on Deterministic Packet Marking and Logging

  • Author

    Wang, Xiao-Jing ; Xiao, You-Lin

  • Author_Institution
    Lab. of Comput. Network Defense Technol., Beijing Inst. of Technol., Beijing, China
  • fYear
    2009
  • fDate
    25-27 Sept. 2009
  • Firstpage
    178
  • Lastpage
    182
  • Abstract
    IP traceback mechanisms are a critical part of the defense against IP spoofing and DoS attacks. Currently proposed traceback mechanisms are inadequate to address the traceback problem for the following reasons: they lack incentives for ISPs to deploy IP traceback in their networks; they do not scale to large scale distributed DoS attacks. In this paper, a novel IP traceback approach based on packet logging and deterministic packet marking (LDPM) is proposed, that significantly improves IP traceback in several aspects: (1) LDPM is built on a distributed hierarchical IP traceback system, and is simple to deploy. (2) LDPM uses a new IP header encoding scheme to store the complete identification information of a router into a single packet, thus it can protect the privacy of network topology and victims can identify attack ingress router with one packet. It also can cope with large distributed attacks with thousands of attackers. (3) LDPM can manipulate the marking information at the edge ingress routers. Therefore, as a value-added services, ISPs can provide traceback business to their customers. Compared with previous traceback schemes, LDPM improves the performance and practicability of IP traceback.
  • Keywords
    IP networks; telecommunication network routing; telecommunication network topology; telecommunication security; DoS attack; IP header encoding scheme; IP spoofing attack; IP traceback mechanism; attack ingress router; deterministic packet logging; deterministic packet marking; distributed hierarchical IP traceback system; network topology privacy protection; single packet router; Computer crime; Computer networks; Embedded computing; Encoding; IP networks; Information security; Large-scale systems; Network topology; Privacy; Protection; IP traceback; deterministic packet marking; distributed denial of service; network security; packet logging;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Scalable Computing and Communications; Eighth International Conference on Embedded Computing, 2009. SCALCOM-EMBEDDEDCOM'09. International Conference on
  • Conference_Location
    Dalian
  • Print_ISBN
    978-0-7695-3825-9
  • Type

    conf

  • DOI
    10.1109/EmbeddedCom-ScalCom.2009.40
  • Filename
    5341555