An IP Traceback Technique against Denial-of-Service Attacks

  • Authors:
  • Zhaole Chen;Moon-Chuen Lee

  • Affiliations:
  • -;-

  • Venue:
  • ACSAC '03 Proceedings of the 19th Annual Computer Security Applications Conference
  • Year:
  • 2003

Quantified Score

Hi-index 0.00

Visualization

Abstract

Reflector attack [9] belongs to one of the most serioustypes of Denial-of-Service (DoS) attacks, which canhardly be traced by contemporary traceback techniques,since the marked information written by any routersbetween the attacker and the reflectors will be lost in thereplied packets from the reflectors. We propose in thispaper a reflective algebraic marking scheme for tracingDoS and DDoS attacks, as well as reflector attacks. Theproposed marking scheme contains three algorithms,namely the marking, reflection and reconstructionalgorithms, which have been well tested through extensivesimulation experiments. The results show that the markingscheme can achieve a high performance in tracing thesources of the potential attack packets. In addition, itproduces negligible false positives; whereas other currentmethods usually produce a certain amount of falsepositives.