• DocumentCode
    2408896
  • Title

    A Stateless Traceback Technique for Identifying the Origin of Attacks from a Single Packet

  • Author

    Moreira, Marcelo D D ; Laufer, Rafael P. ; Fernandes, Natalia C. ; Duarte, Otto Carlos M B

  • Author_Institution
    Univ. Fed. do Rio de Janeiro, Rio de Janeiro, Brazil
  • fYear
    2011
  • fDate
    5-9 June 2011
  • Firstpage
    1
  • Lastpage
    6
  • Abstract
    Anonymity is one of the main motivations for conducting denial-of-service attacks. Currently, there is no mechanism to either identify the true source of an IP packet or to prove its authenticity. In this paper we propose a stateless IP traceback technique that identifies the origin network of each individual packet. We show that the proposed traceback system is the only one that scales with the number of attackers and also satisfies practical requirements, such as no state stored at routers and a header overhead (25 bits) that can be allocated in IPv4 header. The proposed system exploits the customer-provider hierarchy of the Internet at autonomous system (AS) level and introduces the idea of checkpoints, which are the two most important nodes in an AS-level path. Simulation results using a real-world topology trace show that the proposed system narrows the source of an attack packet down to less than two candidate ASes on average. In addition, considering a partial deployment scenario, we show that the proposed system is able to successfully trace more than 90% of the attacks if only 8% of the ASes (i.e., just the core ASes) implement the system. The achieved success rate is quite better than using the classical hop-by-hop path reconstruction.
  • Keywords
    IP networks; Internet; telecommunication network routing; AS level; IP packet; IPv4 header; Internet; autonomous system level; customer-provider hierarchy; denial-of-service attacks; hop-by-hop path reconstruction; routers; single packet; stateless IP traceback technique; Accuracy; IEEE Communications Society; IP networks; Internet; Peer to peer computing; Probabilistic logic; Topology;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Communications (ICC), 2011 IEEE International Conference on
  • Conference_Location
    Kyoto
  • ISSN
    1550-3607
  • Print_ISBN
    978-1-61284-232-5
  • Electronic_ISBN
    1550-3607
  • Type

    conf

  • DOI
    10.1109/icc.2011.5962652
  • Filename
    5962652