STF-DM: A Sparsely Tagged Fragmentation with Dynamic Marking an IP Traceback Approach

被引:0
|
作者
Patel, Hasmukh [1 ]
Jinwala, Devesh [2 ]
机构
[1] Gujarat Technol Univ, Comp Engn Dept, Ahmadabad, Gujarat, India
[2] Sardar Vallabhbhai Natl Inst Technol, Comp Engn Dept, Surat, Gujarat, India
关键词
DDoS attack; IP fraceback; probabilistic packet marking; dynamic marking; sparsely tagged marking; DETERMINISTIC PACKET MARKING; SCHEME;
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Denial of Service (DoS) and Distributed Denial of Service (DDoS) attacks are serious threats to the Internet. The frequency of DoS and DDoS attacks is increasing day by day. Automated tools are also available that enable non-technical people to implement such attacks easily. Hence, it is not only important to prevent such attacks, but also need to trace back the attackers. Tracing back the sources of the attacks, which is known as an IP traceback problem is a hard problem because of the stateless nature of the Internet and spoofed Internet Protocol (IP) packets. Various approaches have been proposed for IP traceback. Probabilistic Packet Marking (PPM) approach incurs the minimum network and management overhead. Hence, we focus on PPM approach. Sparsely-Tagged Fragmentation Marking Scheme (S-TFMS), a PPM based approach, requires low overhead at the victim and achieve zero false-positives. However, it requires a large number of packets to recover the IP addresses. In this paper, we propose a Sparsely-Tagged Fragmentation Marking approach with dynamic marking probability. Our approach requires less number of packets than required by S-TFMS. Further, to reduce the number of packets required by victim, we extend our basic approach with the new marking format. Our extended approach requires less than one-tenth time number of packets than those in S-TFMS approach to recover the IP addresses. Our approaches recover the IP address quickly with zero false-positives in the presence of multiple attackers. We show mathematical as well as experimental analysis of our approaches.
引用
收藏
页码:721 / 728
页数:8
相关论文
共 3 条
  • [1] Dynamic probabilistic packet marking for efficient IP traceback
    Liu, Jenshiuh
    Lee, Zhi-Jian
    Chung, Yeh-Ching
    COMPUTER NETWORKS, 2007, 51 (03) : 866 - 882
  • [2] DDPM:Dynamic deterministic packet marking for IP traceback
    Shokri, Reza
    Varshovi, Ali
    Mohammadi, Hossein
    Yazdani, Nasser
    Sadeghian, Babak
    ICON: 2006 IEEE INTERNATIONAL CONFERENCE ON NETWORKS, VOLS 1 AND 2, PROCEEDINGS: NETWORKING -CHALLENGES AND FRONTIERS, 2006, : 312 - +
  • [3] Efficient dynamic probabilistic packet marking for IP traceback
    Liu, JS
    Lee, ZJ
    Chung, YC
    ICON 2003: 11TH IEEE INTERNATIONAL CONFERENCE ON NETWORKS, 2003, : 475 - 480