• DocumentCode
    2625548
  • Title

    IP traceback marking scheme based packets filtering mechanism

  • Author

    Ping, Sharon Yan ; Moonchuen, Lee

  • Author_Institution
    Comput. Sci. & Eng., Chinese Univ. of Hong Kong, China
  • fYear
    2004
  • fDate
    11-13 Oct. 2004
  • Firstpage
    253
  • Lastpage
    260
  • Abstract
    Denial of service attacks have become one of the most serious threats to the Internet community. One effective means to defend against such attacks is to locate the attack source(s) and to filter out the attack traffic. To locate the attack source(s), this paper proposes an adaptive packet marking scheme for IP traceback, which supports two types of marking. A participating border router would perform deterministic router id marking when a packet enters the network for the first time, and probabilistic domain id marking when it receives a packet from another domain. After collecting sufficient packets, the victim would reconstruct the attack graph incorporating attack paths and the source router(s) identified, with each node on the paths viewed as a domain. Based on the attack graph traced back we propose to let the filtering agent(s) inspect the markings inscribed in the received packets and filter the packets with a marking matching with the attack signatures. Simulation results show that the proposed marking scheme outperforms other IP traceback methods as it requires fewer packets for attack paths reconstruction, and can handle large number of attack sources effectively with relatively low false positives produced. Meanwhile, with the attack packets filtering mechanism, around 80% attack traffic would be removed and the normal traffic can be efficiently preserved in order to restore the victim´s service.
  • Keywords
    IP networks; Internet; filtering theory; telecommunication network routing; telecommunication services; IP traceback marking scheme; Internet; attack packets filtering mechanism; attack source; attack traffic; border router; denial of service attacks; filtering agent; Availability; Computer crime; Computer science; Information filtering; Information filters; Matched filters; Telecommunication traffic; Throughput; Traffic control; Web and internet services; DDoS attacks; IP traceback; inter-domain marking; probabilistic packet marking; source router;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    IP Operations and Management, 2004. Proceedings IEEE Workshop on
  • Print_ISBN
    0-7803-8836-4
  • Type

    conf

  • DOI
    10.1109/IPOM.2004.1547625
  • Filename
    1547625