• DocumentCode
    3018326
  • Title

    Large-scale IP traceback in high-speed Internet: practical techniques and theoretical foundation

  • Author

    Li, Jun ; Sung, Minho ; Xu, Jun ; Li, Li

  • Author_Institution
    Coll. of Comput., Georgia Inst. of Technol., Atlanta, GA, USA
  • fYear
    2004
  • fDate
    9-12 May 2004
  • Firstpage
    115
  • Lastpage
    129
  • Abstract
    Tracing attack packets to their sources, known as IP traceback, is an important step to counter distributed denial-of-service (DDoS) attacks. In this paper, we propose a novel packet logging based (i.e., hash-based) traceback scheme that requires an order of magnitude smaller processing and storage cost than the hash-based scheme proposed by Snoeren, et al. (2001), thereby being able to scalable to much higher link speed (e.g., OC-768). The baseline idea of our approach is to sample and log a small percentage (e.g., 3.3%) of packets. The challenge of this low sampling rate is that much more sophisticated techniques need to be used for traceback. Our solution is to construct the attack tree using the correlation between the attack packets sampled by neighboring routers. The scheme using naive independent random sampling does not perform well due to the low correlation between the packets sampled by neighboring routers. We invent a sampling scheme that improves this correlation and the overall efficiency significantly. Another major contribution of this work is that we introduce a novel information-theoretic framework for our traceback scheme to answer important questions on system parameter tuning and the fundamental trade-off between the resource used for traceback and the traceback accuracy. Simulation results based on real-world network topologies (e.g. Skitter) match very well with results from the information-theoretic analysis. The simulation results also demonstrate that our traceback scheme can achieve high accuracy, and scale very well to a large number of attackers (e.g., 5000+).
  • Keywords
    Internet; packet switching; telecommunication network routing; telecommunication security; Internet; attack packet tracing; attack tree construction; distributed denial-of-service attacks; hash-based scheme; large-scale IP traceback; neighboring router; network topologies; packet logging based traceback; random sampling; system parameter tuning; Internet; Large-scale systems; Privacy; Security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Security and Privacy, 2004. Proceedings. 2004 IEEE Symposium on
  • ISSN
    1081-6011
  • Print_ISBN
    0-7695-2136-3
  • Type

    conf

  • DOI
    10.1109/SECPRI.2004.1301319
  • Filename
    1301319