Tracing attackers with deterministic edge router marking (DERM)

  • Authors:
  • Shravan K. Rayanchu;Gautam Barua

  • Affiliations:
  • Samsung India Software Operations, Bangalore, India;Dept of CSE, IIT Guwahati, Guwahati, India

  • Venue:
  • ICDCIT'04 Proceedings of the First international conference on Distributed Computing and Internet Technology
  • Year:
  • 2004

Quantified Score

Hi-index 0.00

Visualization

Abstract

Tracing the attackers in a distributed denial-of-service(DDoS) attack is particularly difficult since attackers spoof the source addresses We present a novel approach to IP Traceback – Deterministic Edge Router Marking (DERM) The proposed scheme is scalable to thousands of attackers, is very simple to implement at the routers, has no bandwidth overhead and needs minimal processing and storage requirements at the victim As each complete mark fits into a single packet, our scheme can also be used for per-packet filtering and as a congestion signature in a pushback protocol The traceback procedure requires a small number of packets and can be performed during the post-mortem analysis of an attack Only limited co-operation is required from Internet Service Providers (ISP) They do not have to reveal the topology of their internal networks.