• DocumentCode
    888348
  • Title

    Novel hybrid schemes employing packet marking and logging for IP traceback

  • Author

    Al-Duwairi, Basheer ; Govindarasu, Manimaran

  • Author_Institution
    Dept. of Comput. Eng., Jordan Univ. of Sci. & Technol., Irbid, Jordan
  • Volume
    17
  • Issue
    5
  • fYear
    2006
  • fDate
    5/1/2006 12:00:00 AM
  • Firstpage
    403
  • Lastpage
    418
  • Abstract
    Tracing DoS attacks that employ source address spoofing is an important and challenging problem. Traditional traceback schemes provide spoofed packets traceback capability either by augmenting the packets with partial path information (i.e., packet marking) or by storing packet digests or signatures at intermediate routers (i.e., packet logging). Such approaches require either a large number of attack packets to be collected by the victim to infer the paths (packet marking) or a significant amount of resources to be reserved at intermediate routers (packet logging). We adopt a hybrid traceback approach in which packet marking and packet logging are integrated in a novel manner, so as to achieve the best of both worlds, that is, to achieve a small number of attack packets to conduct the traceback process and a small amount of resources to be allocated at intermediate routers for packet logging purposes. Based on this notion, two novel traceback schemes are presented. The first scheme, called distributed link-list traceback (DLLT), is based on the idea of preserving the marking information at intermediate routers in such a way that it can be collected using a link list-based approach. The second scheme, called probabilistic pipelined packet marking (PPPM), employs the concept of a "pipeline" for propagating marking information from one marking router to another so that it eventually reaches the destination. We evaluate the effectiveness of the proposed schemes against various performance metrics through a combination of analytical and simulation studies. Our studies show that the proposed schemes offer a drastic reduction in the number of packets required to conduct the traceback process and a reasonable saving in the storage requirement.
  • Keywords
    IP networks; packet switching; quality of service; telecommunication network routing; telecommunication security; DLLT; DoS attacks; IP traceback; PPPM; distributed link-list traceback; employing packet marking; hybrid traceback approach; intermediate router; partial path information; probabilistic pipelined packet marking; storing packet digests; Analytical models; Computer crime; Delay; Information filtering; Information filters; Measurement; Performance analysis; Resource management; Security; Web and internet services; DDoS attacks; IP traceback.; Internet security;
  • fLanguage
    English
  • Journal_Title
    Parallel and Distributed Systems, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    1045-9219
  • Type

    jour

  • DOI
    10.1109/TPDS.2006.63
  • Filename
    1613850