Detecting third-party addresses in traceroute traces with IP timestamp option

  • Authors:
  • Pietro Marchetta;Walter de Donato;Antonio Pescapé

  • Affiliations:
  • University of Napoli Federico II, Italy;University of Napoli Federico II, Italy;University of Napoli Federico II, Italy

  • Venue:
  • PAM'13 Proceedings of the 14th international conference on Passive and Active Measurement
  • Year:
  • 2013

Quantified Score

Hi-index 0.00

Visualization

Abstract

Traceroute is one of the most famous and widely adopted diagnostic tool for computer networks. Although traceroute is often used to infer links between Autonomous Systems (ASes), the presence of the so-called third-party (TP) addresses may induce the inference of false AS-level links. In this paper, we propose a novel active probing technique based on the IP timestamp option able to identify TP addresses. For evaluating both the applicability and the utility of the proposed technique, we perform a large-scale measurement campaign targeting --- from multiple vantage points --- more than 327K destinations belonging to about 14K ASes. The results show how TP addresses are very common and affect about 17% of AS-level links extracted from traceroute traces. Compared to a previously proposed heuristic method, our technique allows to identify many more TP addresses and to re-interpret part of its results.