4.7 Article

Flexible Deterministic Packet Marking: An IP Traceback System to Find the Real Source of Attacks

期刊

出版社

IEEE COMPUTER SOC
DOI: 10.1109/TPDS.2008.132

关键词

DDoS attacks; IP traceback; performance evaluation; routers; security

资金

  1. ARC Discovery grant [DP0773264]
  2. National High-Tech Research and Development Plan of China (863 Plan) [2008AA01Z106, 2006AA01Z202]
  3. National Natural Science Foundation of China [60811130528, 60725208, 60533040]
  4. Shanghai Pujiang Plan [07pj14049]

向作者/读者索取更多资源

Internet Protocol (IP) traceback is the enabling technology to control Internet crime. In this paper, we present a novel and practical IP traceback system called Flexible Deterministic Packet Marking (FDPM) which provides a defense system with the ability to find out the real sources of attacking packets that traverse through the network. While a number of other traceback schemes exist, FDPM provides innovative features to trace the source of IP packets and can obtain better tracing capability than others. In particular, FDPM adopts a flexible mark length strategy to make it compatible to different network environments; it also adaptively changes its marking rate according to the load of the participating router by a flexible flow-based marking scheme. Evaluations on both simulation and real system implementation demonstrate that FDPM requires a moderately small number of packets to complete the traceback process; add little additional load to routers and can trace a large number of sources in one traceback process with low false positive rates. The built-in overload prevention mechanism makes this system capable of achieving a satisfactory traceback result even when the router is heavily loaded. The motivation of this traceback system is from DDoS defense. It has been used to not only trace DDoS attacking packets but also enhance filtering attacking traffic. It has a wide array of applications for other security systems.

作者

我是这篇论文的作者
点击您的名字以认领此论文并将其添加到您的个人资料中。

评论

主要评分

4.7
评分不足

次要评分

新颖性
-
重要性
-
科学严谨性
-
评价这篇论文

推荐

暂无数据
暂无数据