Autonomous System based Flow Marking Scheme for IP-Traceback

被引:0
作者
Aghaei-Foroushani, Vahid [1 ]
Zincir-Heywood, A. Nur [1 ]
机构
[1] Dalhousie Univ, Fac Comp Sci, Halifax, NS, Canada
来源
NOMS 2016 - 2016 IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM | 2016年
关键词
AS-level IP-Traceback; Flow Base IP-Traceback; Probabilistic Flow Marking; DDoS attacks; Network Security; NETWORK;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Tracing IP packets to their sources, known as IP-Traceback, is a critical task in defending against IP spoofing and DoS attacks. There are several solutions to traceback to the origin of the attack. However, all these solutions require either all routers or ISPs to support the same IP-Traceback mechanism. To address this limitation, we propose an IP-Traceback approach at the level of autonomous systems, called Autonomous System-based Flow Marking, ASFM, to identify some key locations in the path where attacker packets are being forwarded. ASFM employs the BGP update message community attribute that enables information to be passed across ASs even if they are not necessarily involved in the IP-Traceback scheme. We also propose an authentication method, so a downstream AS can examine the correctness of the marking provided by the upstream ASs, thus eliminating the fake marking embedded by subverted routers. Finally, we evaluate and analyze the performance of our proposal, using real life datasets.
引用
收藏
页码:121 / 128
页数:8
相关论文
共 28 条
  • [1] Aghaei-Foroushani V., 2013, 27 IEEE INT C ADV IN, V5, P25
  • [2] Aghaei-Foroushani V., 2013, EURASIP J INFORM SEC, V5
  • [3] Aghaei-Foroushani V, 2015, PROCEEDINGS OF THE 2015 IFIP/IEEE INTERNATIONAL SYMPOSIUM ON INTEGRATED NETWORK MANAGEMENT (IM), P762, DOI 10.1109/INM.2015.7140370
  • [4] Aghaei-Foroushani V, 2015, 2015 7TH INTERNATIONAL WORKSHOP ON RELIABLE NETWORKS DESIGN AND MODELING (RNDM) PROCE4EDINGS, P229, DOI 10.1109/RNDM.2015.7325234
  • [5] On Evaluating IP Traceback Schemes: A Practical Perspective
    Aghaei-Foroushani, Vahid
    Zincir-Heywood, A. Nur
    [J]. IEEE CS SECURITY AND PRIVACY WORKSHOPS (SPW 2013), 2013, : 127 - 134
  • [6] Alenezi M. J., 2013, P IEEE INT C COMP AP, P1
  • [7] [Anonymous], 1995, 1771 RFC
  • [8] [Anonymous], 2015, CAIDA SKITTER AS LIN
  • [9] [Anonymous], 2015, CAIDA DDOS ATTACK 20
  • [10] [Anonymous], 2015, CIDR REP