SVM based packet marking technique for traceback on malicious DDoS traffic

  • Authors:
  • Hyung-Woo Lee

  • Affiliations:
  • Div of Computer, Information and Software, Hanshin University, Osan, Gyunggi, Korea

  • Venue:
  • ICOIN'06 Proceedings of the 2006 international conference on Information Networking: advances in Data Communications and Wireless Networks
  • Year:
  • 2006

Quantified Score

Hi-index 0.00

Visualization

Abstract

Distributed Denial-of-Service(DDoS) attack can be done by generating a large volume of traffic through spoofing the IP address of DoS attacker The e-mail based attack is also similar with existing DDoS attack in network traffic status In response to such attacks, IP traceback technology has been proposed For example, the method identifies the source of a spoofed e-mail attack and restructures the path on the network through which the attacking packet has been transmitted This study proposed an improved marking technique that identifies DDoS traffics with TTL information at routers by applying the SVM module for malicious traffic control and cope with DDoS attack packets efficiently According to the result of experiments, the proposed technique reduced network load and improved filter/traceback performance.