DocumentCode :
1677903
Title :
TTL Based Packet Marking for IP Traceback
Author :
Paruchuri, Vamsi ; Durresi, Arjan ; Chellappan, Sriram
Author_Institution :
Dept. of Comput. Sci., Univ. of Central Arkansas, Conway, AR
fYear :
2008
Firstpage :
1
Lastpage :
5
Abstract :
Distributed denial of service attacks continue to pose major threats to the Internet. In order to traceback attack sources (i.e., IP addresses), a well studied approach is probabilistic packet marking (PPM), where each intermediate router of a packet marks it with a certain probability, enabling a victim host to traceback the attack source. In a recent study, we showed how attackers can take advantage of probabilistic nature of packet markings in existing PPM schemes to create spoofed marks, hence compromising traceback. In this paper, we propose a new PPM scheme called TTL-based PPM (TPM) scheme, where each packet is marked with a probability inversely proportional to the distance traversed by the packet so far. Thus, packets that have to traverse longer distances are marked with higher probability, compared to those that have to traverse shorter distances. This ensures that a packet is marked with much higher probability by intermediate routers than by traditional mechanisms, hence reducing the effectiveness of spoofed packets reaching victims. Using formal analysis and simulations using real Internet topology maps, we show how our TPM scheme can effectively trace DDoS attackers even in presence of spoofing when compared to existing schemes.
Keywords :
IP networks; Internet; probability; telecommunication network routing; telecommunication network topology; telecommunication security; DDoS attack; IP traceback; Internet; TTL based packet marking; distributed denial of service attack; network topology map; packet router; probabilistic packet marking; probability; Analytical models; Computer crime; Delay; Intrusion detection; Routing; Topology; Web and internet services;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Global Telecommunications Conference, 2008. IEEE GLOBECOM 2008. IEEE
Conference_Location :
New Orleans, LO
ISSN :
1930-529X
Print_ISBN :
978-1-4244-2324-8
Type :
conf
DOI :
10.1109/GLOCOM.2008.ECP.490
Filename :
4698265
Link To Document :
بازگشت