Enhanced and authenticated deterministic packet marking for IP traceback

  • Authors:
  • Dan Peng;Zhicai Shi;Longming Tao;Wu Ma

  • Affiliations:
  • Information Engineering Institute, Dalian University, Dalian, Liaoning, China;Information Engineering Institute, Dalian University, Dalian, Liaoning, China;Information Engineering Institute, Dalian University, Dalian, Liaoning, China;Information Engineering Institute, Dalian University, Dalian, Liaoning, China

  • Venue:
  • APPT'07 Proceedings of the 7th international conference on Advanced parallel processing technologies
  • Year:
  • 2007

Quantified Score

Hi-index 0.00

Visualization

Abstract

The rising threat of cyber attacks, especially distributed denial-of-service (DDos), makes the IP traceback problem very relevant to today's Internet security. In this paper, a novel deterministic packet marking scheme called PN-DPM for IP traceback is presented. Through a unique technique: path numbering, our scheme provides ISPs a feasible solution to make IP traceback as a value-added network service, which allows the victim not only to detect and filter spoofed DDOS attacks immediately, but also to obtain more accurate information about the source of the attacks from the corresponding ISPs by the authenticated marks, even after the attacks has been completed. Our techniques feature low network and router overhead, low computational load for victim, and support incremental deployment. In contrast to previous work, our technique has significantly higher feasibility by considering much more aspects of IP traceback technology from practical perspective.