A Fractional-Step DDoS Attack Source Traceback Algorithm Based on Autonomous System

  • Authors:
  • Zhaoyang Qu;Chunfeng Huang

  • Affiliations:
  • -;-

  • Venue:
  • IIH-MSP '08 Proceedings of the 2008 International Conference on Intelligent Information Hiding and Multimedia Signal Processing
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

This paper proposes a fractional-step algorithm based on Autonomous System(AS) to trace Distributed Denial of Service (DDoS) attack source by dividing the tracing process into two steps. In the first step, Deterministic Packet Marking based on AS (ASDPM) is adopted to determine the attack-originating AS. In the second step, Non-repeated Probabilistic Packet Marking(NRPPM) is used to identify the exact origin of the attacks in the specific AS. Compared with previous algorithms, the two-step traceback algorithm has the benefits of low bandwidth consumption, quick convergence speed, light computational overhead and low false positive, it can decrease the number of packets the path reconstruction needs, and increase the efficiency of path reconstruction, hence making it possible to trace the DDoS attack source on a real-time basis.