Efficient dynamic probabilistic packet marking for IP traceback

被引:0
作者
Liu, JS [1 ]
Lee, ZJ [1 ]
Chung, YC [1 ]
机构
[1] Feng Chia Univ, Dept Informat Engn & Comp Sci, Taichung 407, Taiwan
来源
ICON 2003: 11TH IEEE INTERNATIONAL CONFERENCE ON NETWORKS | 2003年
关键词
denial of service; IP; network security; probabilistic packet marking; traceback;
D O I
暂无
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
Recently, Denial-of-service (DoS) attack has become a pressing problem due to lack of efficient method to locate the real attackers and easy to execute with readily available source codes on the Internet. Traceback is a subtle scheme to tackle the DoS attacks. The probabilistic packet marking (PPM) is a new way for practical IP traceback. Although the PPM enables a victim to pinpoint the attacker's origin to within 25 equally possible sites, it have been shown that PPM suffers from uncertainty under attack with spoofed packets. In this work, we present a new approach, called dynamic probabilistic packet marking(DPPM), to further improve effectiveness of PPM. Instead of using a fixed marking probability, we propose to deduce how far a packet has traveled and then choose the marking probability as an inverse function of hop count traveled. The DPPM may remove uncertainty completely and enable victims to precisely pinpoint attacking origin under DoS attacks. Our proposed DPPM can be applied to DDoS attacks with a very limited uncertainty.
引用
收藏
页码:475 / 480
页数:6
相关论文
共 50 条
  • [31] IP traceback marking scheme based packets filtering mechanism
    Ping, SY
    Lee, MC
    2004 IEEE Workshop on IP Operations and Management Proceedings (IPOM 2004): SELF-MEASUREMENT & SELF-MANAGEMENT OF IP NETWORKS & SERVICES, 2004, : 253 - 260
  • [32] A practical and robust inter-domain marking scheme for IP traceback
    Gao, Zhiqiang
    Ansari, Nirwan
    COMPUTER NETWORKS, 2007, 51 (03) : 732 - 750
  • [33] Autonomous System based Flow Marking Scheme for IP-Traceback
    Aghaei-Foroushani, Vahid
    Zincir-Heywood, A. Nur
    NOMS 2016 - 2016 IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM, 2016, : 121 - 128
  • [34] A new approach of IP traceback with multiple marking tags for DoS attacks
    Li, S., 1600, Xi'an Jiaotong University (47): : 13 - 17
  • [35] Tracemax: A Novel Single Packet IP Traceback Strategy for Data-Flow Analysis
    Hillmann, Peter
    Tietze, Frank
    Rodosek, Gabi Dreo
    40TH ANNUAL IEEE CONFERENCE ON LOCAL COMPUTER NETWORKS (LCN 2015), 2015, : 177 - 180
  • [36] Extensions to the source path isolation engine for precise and efficient log-based IP traceback
    Hilgenstieler, Egon
    Duarte, Elias P., Jr.
    Mansfield-Keeni, Glenn
    Shiratori, Norio
    COMPUTERS & SECURITY, 2010, 29 (04) : 383 - 392
  • [37] A method of IP traceback for DOS
    Wang, Y
    Li, YC
    Zhang, XS
    Zeng, JZ
    PARALLEL AND DISTRIBUTED COMPUTING, APPLICATIONS AND TECHNOLOGIES, PDCAT'2003, PROCEEDINGS, 2003, : 762 - 764
  • [38] HPSIPT: A high-precision single-packet IP traceback scheme
    Murugesan, Vijayalakshmi
    Selvaraj, Mercy Shalinie
    Yang, Ming-Hour
    COMPUTER NETWORKS, 2018, 143 : 275 - 288
  • [39] Improved probabilistic packet marking scheme based on APPM-v6
    Feng Bo
    He Yusheng
    2014 IEEE 7TH JOINT INTERNATIONAL INFORMATION TECHNOLOGY AND ARTIFICIAL INTELLIGENCE CONFERENCE (ITAIC), 2014, : 380 - 385
  • [40] A Prediction Based Approach to IP Traceback
    Kiremire, Ankunda R.
    Brust, Matthias R.
    Phoha, Vir V.
    PROCEEDINGS OF THE 37TH ANNUAL IEEE CONFERENCE ON LOCAL COMPUTER NETWORKS WORKSHOPS (LCN 2012), 2012, : 1022 - 1029