DocumentCode
2625548
Title
IP traceback marking scheme based packets filtering mechanism
Author
Ping, Sharon Yan ; Moonchuen, Lee
Author_Institution
Comput. Sci. & Eng., Chinese Univ. of Hong Kong, China
fYear
2004
fDate
11-13 Oct. 2004
Firstpage
253
Lastpage
260
Abstract
Denial of service attacks have become one of the most serious threats to the Internet community. One effective means to defend against such attacks is to locate the attack source(s) and to filter out the attack traffic. To locate the attack source(s), this paper proposes an adaptive packet marking scheme for IP traceback, which supports two types of marking. A participating border router would perform deterministic router id marking when a packet enters the network for the first time, and probabilistic domain id marking when it receives a packet from another domain. After collecting sufficient packets, the victim would reconstruct the attack graph incorporating attack paths and the source router(s) identified, with each node on the paths viewed as a domain. Based on the attack graph traced back we propose to let the filtering agent(s) inspect the markings inscribed in the received packets and filter the packets with a marking matching with the attack signatures. Simulation results show that the proposed marking scheme outperforms other IP traceback methods as it requires fewer packets for attack paths reconstruction, and can handle large number of attack sources effectively with relatively low false positives produced. Meanwhile, with the attack packets filtering mechanism, around 80% attack traffic would be removed and the normal traffic can be efficiently preserved in order to restore the victim´s service.
Keywords
IP networks; Internet; filtering theory; telecommunication network routing; telecommunication services; IP traceback marking scheme; Internet; attack packets filtering mechanism; attack source; attack traffic; border router; denial of service attacks; filtering agent; Availability; Computer crime; Computer science; Information filtering; Information filters; Matched filters; Telecommunication traffic; Throughput; Traffic control; Web and internet services; DDoS attacks; IP traceback; inter-domain marking; probabilistic packet marking; source router;
fLanguage
English
Publisher
ieee
Conference_Titel
IP Operations and Management, 2004. Proceedings IEEE Workshop on
Print_ISBN
0-7803-8836-4
Type
conf
DOI
10.1109/IPOM.2004.1547625
Filename
1547625
Link To Document