DocumentCode
2329935
Title
NXG01-4: Scalable Hierarchical Traceback
Author
Durresi, Arjan ; Paruchuri, Vamsi
Author_Institution
Dept. of Comput. Sci., Louisiana State Univ., Baton Rouge, LA
fYear
2006
fDate
Nov. 27 2006-Dec. 1 2006
Firstpage
1
Lastpage
5
Abstract
Distributed Denial of Service attacks have recently emerged as one of the most potent, if not the greatest, weaknesses of the Internet. Previous solutions for this problem try to traceback to the exact origin of the attack by requiring the participation of all routers. For many reasons this requirement is impractical. In the presence of non-participating routers most of the proposed schemes either fail in reconstructing the attack path or end up with an approximate location of the attacker. We propose Hierarchical IP Traceback (HIT), a hierarchical approach to address this issue. HIT has significant improvements over other works in several dimensions: (1) with just a few tens of packets, HIT enables the victim to reconstruct the attack graph, an improvement of 2-3 orders of magnitude when compared to previous schemes; (2) HIT scales to large distributed attacks with thousands of attacks; (3) owing to its hierarchical nature, the reconstruction takes only tens of seconds.
Keywords
IP networks; Internet; telecommunication services; Internet; attack graph reconstruction; distributed denial of service attacks; routers; scalable hierarchical IP traceback; Computer crime; Computer science; Filtering; IP networks; Mechanical factors; Protocols; Scalability; Telecommunication traffic; Topology; Web and internet services;
fLanguage
English
Publisher
ieee
Conference_Titel
Global Telecommunications Conference, 2006. GLOBECOM '06. IEEE
Conference_Location
San Francisco, CA
ISSN
1930-529X
Print_ISBN
1-4244-0356-1
Electronic_ISBN
1930-529X
Type
conf
DOI
10.1109/GLOCOM.2006.321
Filename
4150951
Link To Document