Improved probabilistic packet marking scheme based on APPM-v6

被引:0
作者
Feng Bo [1 ]
He Yusheng [1 ]
机构
[1] JiangXi Commun Adm, Nanchang, Peoples R China
来源
2014 IEEE 7TH JOINT INTERNATIONAL INFORMATION TECHNOLOGY AND ARTIFICIAL INTELLIGENCE CONFERENCE (ITAIC) | 2014年
关键词
IP traceback; IPv6; probabilistic packet marking; attack source; DDoS; network security;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
There are many limitations for the current IPv6 traceback technology advanced probabilistic packet marking scheme-v6 (APPM-v6). These limitations mainly include lack of marking space, fragmentation of marking information, easily to be recovered, a high price for path reconstruction and heavy load on routers. This thesis improved APPM-v6 and proposed improved probabilistic packet marking scheme-v6 (IPPM-v6). It redistributed marking area, which was divided into flag area and information area. Taking advantage of the "hop limit" field in IPv6 basic header, flag area can be used to tell the state of packets. Taking advantage of "routing extension header" field in IPv6 extension header, information area can be used to store the marking information. Besides, it made use of flag area to activate dynamic marking mechanism and differentiated unmarked packets and marked packets to prevent the information being covered, thus to reduce the rate of false positives. Theoretic analysis and experiment prove that IPPM-v6 is superior to APPM-v6 in the rate of false positives, convergence time, the weakest link, etc...
引用
收藏
页码:380 / 385
页数:6
相关论文
共 7 条
  • [1] Mank N A, 2001, IEEE INT C COMM NETW, P158
  • [2] Practical network support for IP traceback
    Savage, S
    Wetherall, D
    Karlin, A
    Anderson, T
    [J]. ACM SIGCOMM COMPUTER COMMUNICATION REVIEW, 2000, 30 (04) : 295 - 306
  • [3] Song D, 2001, P IEEE INF C, P877
  • [4] Ston R, 2000, P USENIX SEC S
  • [5] IP traceback-based intelligent packet filtering: A novel technique for defending against internet DDoS attacks
    Sung, MH
    Xu, J
    [J]. IEEE TRANSACTIONS ON PARALLEL AND DISTRIBUTED SYSTEMS, 2003, 14 (09) : 861 - 872
  • [6] [占勇军 ZHAN Yongjun], 2007, [计算机工程与科学, Computer Engineering and Science], V29, P11
  • [7] Zhao Shu-feng, 2012, COMPUTER ENG DESIGN, P57