GOSSIB vs. IP Traceback Rumors

  • Authors:
  • Marcel Waldvogel

  • Affiliations:
  • -

  • Venue:
  • ACSAC '02 Proceedings of the 18th Annual Computer Security Applications Conference
  • Year:
  • 2002

Quantified Score

Hi-index 0.00

Visualization

Abstract

To identify sources of distributed denial-of-service attacks,path traceback mechanisms have been proposed. Tracebackmechanisms relying on probabilistic packet marking (PPM) havereceived most attention, as they are easy to implement and deployincrementally. In this paper, we introduce a new concept, namelyGroups Of Strongly SImilar Birthdays (GOSSIB 1 ), that can be usedby to obtain effects similar to a successful birthday attack on PPMschemes. The original and most widely known IP traceback mechanism,compressed edge fragment sampling (CEFS), was developedby Savage et al. [SWKA00]. We analyze the effects of an attackerusing GOSSIB against CEFS and show that the attacker can seedmisinformation much more efficiently than the network is able tocontribute real traceback information. Thus, GOSSIB will renderPPM effectively useless. It can be expected that GOSSIB has similareffects on other PPM traceback schemes and that standardmodifications to the systems will not solve the problem.