Deterministic and Authenticated Flow Marking for IP Traceback

被引:9
作者
Foroushani, Vahid Aghaei [1 ]
Zincir-Heywood, A. Nur [1 ]
机构
[1] Dalhousie Univ, Fac Comp Sci, Halifax, NS, Canada
来源
2013 IEEE 27TH INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION NETWORKING AND APPLICATIONS (AINA) | 2013年
关键词
Security; Flow Base IP Traceback; DDoS Attacks; Deterministic Flow Marking; Authenticated Flow Marking;
D O I
10.1109/AINA.2013.60
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
In this paper, we present a novel approach to IP traceback - Deterministic Flow Marking (DFM) - which allows the victim to traceback the origin of incorrect or spoofed source addresses up to the attacker node, even if the attack has been originated from a network behind a NAT or a proxy server. DFM is scalable and simple to implement, it is capable of tracing thousands of simultaneous distributed attacks in near real time. Moreover, it has a small footprint, resulting in low processing and memory overhead at the victim machines and edge routers. Additionally, DFM provides an optional authentication, so that a compromised router cannot forge markings of other uncompromised routers. Our results show that DFM can reach to similar to 99% traceback rate with no false positives.
引用
收藏
页码:397 / 404
页数:8
相关论文
共 28 条
[1]  
Alshammari R., 2011, J COMPUTER NETWORKS
[2]  
[Anonymous], 2006, 2006 14 IEEE INT C N
[3]  
[Anonymous], 2011, INTRO EC CRISIS WHAT
[4]  
[Anonymous], 2000, P 7 ACM C COMP COMM
[5]   On IP traceback [J].
Belenky, A ;
Ansari, N .
IEEE COMMUNICATIONS MAGAZINE, 2003, 41 (07) :142-153
[6]   On deterministic packet marking [J].
Belenky, Andrey ;
Ansari, Nirwan .
COMPUTER NETWORKS, 2007, 51 (10) :2677-2700
[7]  
BELLOVIN S, 2000, ICMP TRACEB IN PRESS
[8]  
Dean D., 2002, ACM Transactions on Information and Systems Security, V5, P119, DOI 10.1145/505586.505588
[9]   A practical and robust inter-domain marking scheme for IP traceback [J].
Gao, Zhiqiang ;
Ansari, Nirwan .
COMPUTER NETWORKS, 2007, 51 (03) :732-750
[10]   Tracing cyber attacks from the practical perspective [J].
Gao, ZQ ;
Ansari, N .
IEEE COMMUNICATIONS MAGAZINE, 2005, 43 (05) :123-131