• DocumentCode
    2552028
  • Title

    A performance evaluation of Route Based Packet Marking (RBPM) for IP trace back

  • Author

    Alwis, Harendra A. ; Doss, Robin C. ; Chowdhury, Morshed U. ; Hewage, Praveen S.

  • Author_Institution
    Sch. of Eng. & Inf. Technol., Deakin Univ., Melbourne, Vic.
  • fYear
    2006
  • fDate
    23-24 Dec. 2006
  • Firstpage
    364
  • Lastpage
    369
  • Abstract
    IP source address spoofing exploits a fundamental security weakness at the network layer of the Internet protocol (IP). IP datagrams with spoofed source address fields are employed in network-based attacks such as session hijacking and denial of service (DoS) to increase the potency of the attack as well as to conceal the identity of the attacker. DoS attacks in particular can be effectively mitigated by tracing attack packets to their source. Packet marking techniques can enable IP packets to be traced back to a point that is close to their actual source. Present packet marking techniques are hindered by compatibility issues between IPv4 and IPv6 and the need for multiple packets from one source for the source address to be identified. We propose a new packet marking method that builds on the flexibility of the packet marking principle, while overcoming the above mentioned shortcomings. We also compare the processing cost of the proposed method with present packet marking methods.
  • Keywords
    IP networks; protocols; telecommunication security; ICMP; IP datagrams; IP source address spoofing; IP trace back; Internet protocol; denial of service attacks; egress filtering; ingress filtering; network-based attacks; performance evaluation; route based packet marking; session hijacking; Communication system security; Computer crime; Computer security; Data security; IP networks; Information filtering; Information filters; Internet; Military computing; Protocols; Denial of Service Attack (DoS); Egress Filtering; ICMP; IP Spoofing; IP Trace-back; Ingress Filtering; Packet Marking; Route Based Packet Marking (RBPM);
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Multitopic Conference, 2006. INMIC '06. IEEE
  • Conference_Location
    Islamabad
  • Print_ISBN
    1-4244-0795-8
  • Electronic_ISBN
    1-4244-0795-8
  • Type

    conf

  • DOI
    10.1109/INMIC.2006.358193
  • Filename
    4196436