A dynamic path identification mechanism to defend against DDoS attacks

  • Authors:
  • GangShin Lee;Heeran Lim;Manpyo Hong;Dong Hoon Lee

  • Affiliations:
  • Center for Information Security Technologies(CIST), Korea University, Seoul, Korea;Internet Immune System Laboratory, Ajou University, Suwon, Korea;Internet Immune System Laboratory, Ajou University, Suwon, Korea;Center for Information Security Technologies(CIST), Korea University, Seoul, Korea

  • Venue:
  • ICOIN'05 Proceedings of the 2005 international conference on Information Networking: convergence in broadband and mobile networking
  • Year:
  • 2005

Quantified Score

Hi-index 0.00

Visualization

Abstract

Many Researchers have tried to design mechanisms to resist Distributed Denial of Service(DDoS) attacks. Unfortunately, any of them has not been satisfactory. Recently, Yaar et al.[1] suggested Pi (short for Path Identifier) marking scheme as one of solutions to thwart DDoS attacks, which is fast and effective in dropping the false positive and negative packets from users and attackers. They make use of the IP Identification field of which length is 16 bits as marking section. Every router en-route to the victim marks 1-bit or 2-bits by wrapping method sequentially. The victim drops the false positive and negative packets according to the attack markings list. The performance of Pi is measured for marking bit size of 1 or 2 bits. This paper suggests the method to decide the marking bit size dynamically in accordance with the number of hop counts. The performance is quite improved, compared with the existing one.