DocumentCode
2684720
Title
A Network Coding Approach to IP Traceback
Author
Sattari, Pegah ; Gjoka, Minas ; Markopoulou, Athina
Author_Institution
Univ. of California, Irvine, CA, USA
fYear
2010
fDate
9-11 June 2010
Firstpage
1
Lastpage
6
Abstract
Traceback schemes aim at identifying the source(s) of a sequence of packets and the nodes these packets traversed. This is useful for tracing the sources of high volume traffic, e.g., in Distributed Denial-of-Service (DDoS) attacks. In this paper, we are particularly interested in Probabilistic Packet Marking (PPM) schemes, where intermediate nodes probabilistically mark packets with information about their identity and the receiver uses information from several packets to reconstruct the paths they have traversed. Our work is inspired by two observations. First, PPM is essentially a coupon collector´s problem. Second, the coupon collector´s problem significantly benefits from network coding ideas. Based on these observations, we propose a network coding-based approach (PPM+NC) that marks packets with random linear combinations of router IDs, instead of individual router IDs. We demonstrate its benefits through analysis. We then propose a practical PPM+NC scheme based on the main PPM+NC idea, but also taking into account the limited bit budget in the IP header available for marking and other practical constraints. Simulation results show that our scheme significantly reduces the number of packets needed to reconstruct the attack graph, in both single- and multi-path scenarios, thus increasing the speed of tracing the attack back to its source(s).
Keywords
IP networks; computer networks; graph theory; network coding; probability; telecommunication network routing; IP header; IP traceback; attack graph; coupon collector problem; network coding; probabilistic packet marking; router ID; source identification; Communication system traffic control; Delay effects; IP networks; Internet; Network coding; Performance analysis; Queueing analysis; Stochastic processes; Telecommunication traffic; Traffic control;
fLanguage
English
Publisher
ieee
Conference_Titel
Network Coding (NetCod), 2010 IEEE International Symposium on
Conference_Location
Toronto, ON
Print_ISBN
978-1-4244-7189-8
Electronic_ISBN
978-1-4244-7188-1
Type
conf
DOI
10.1109/NETCOD.2010.5487682
Filename
5487682
Link To Document