DocumentCode
3537137
Title
Modified Deterministic Packet Marking for DDoS Attack Traceback in IPv6 Network
Author
Sun, You-ye ; Zhang, Cui ; Meng, Shao-qing ; Lu, Kai-ning
Author_Institution
Inf. & Network Center, Tianjin Univ., Tianjin, China
fYear
2011
fDate
Aug. 31 2011-Sept. 2 2011
Firstpage
245
Lastpage
248
Abstract
Although possible security threats were taken into consideration when IPv6 was formulated, attacks, especially distributed denial-of-service (DDoS), still exist in IPv6 network. This makes IP trace back schemes very relevant to the security of IPv6 network. As many current IP trace back schemes are designed according to IPv4, they can not be directly used in IPv6 network. A modified Deterministic Packet Marking (DPM) for DDoS attack trace back in IPv6 network is presented in this work. This method is able to trace a huge number of simultaneous DDoS attackers. As the trace back process can be performed post-mortem, it can also trace the attacks that have not been noticed at first. Besides, it only takes a small amount of marked packets to complete the trace back process. It is also simple to implement and consumes practically no additional processing overhead on the network equipments. Although the initial motivation of modified DPM is to trace DDoS attack, it can also be used to filter anomaly traffic in IPv6 network.
Keywords
IP networks; telecommunication security; telecommunication traffic; DDoS attack traceback; DPM; IP traceback schemes; IPv4; IPv6 network; anomaly traffic; distributed denial-of-service; modified deterministic packet marking; Computer crime; Convergence; Encoding; IP networks; Probabilistic logic; Routing; DDoS; DPM; Destination Options Header; IPv6; convergence time; false positive rate;
fLanguage
English
Publisher
ieee
Conference_Titel
Computer and Information Technology (CIT), 2011 IEEE 11th International Conference on
Conference_Location
Pafos
Print_ISBN
978-1-4577-0383-6
Electronic_ISBN
978-0-7695-4388-8
Type
conf
DOI
10.1109/CIT.2011.59
Filename
6036763
Link To Document