DocumentCode :
2625539
Title :
Trace IP packets by flexible deterministic packet marking (FDPM)
Author :
Xiang, Yang ; Zhou, Wanlei
Author_Institution :
Sch. of Inf. Technol., Deakin Univ., Melbourne, Vic., Australia
fYear :
2004
fDate :
11-13 Oct. 2004
Firstpage :
246
Lastpage :
252
Abstract :
Currently a large number of the notorious distributed denial of service (DDoS) attack incidents make people aware of the importance of the IP traceback technique. IP traceback is the ability to trace the IP packets to their origins. It provides a security system with the capability of identifying the true sources of the attacking IP packets. IP traceback mechanisms have been researched for years, aiming at finding the sources of IP packets quickly and precisely. In this paper, an IP traceback scheme, flexible deterministic packet marking (FDPM), is proposed. It provides more flexible features to trace the IP packets and can obtain better tracing capability over other IP traceback mechanisms, such as link testing, messaging, logging, probabilistic packet marking (PPM), and deterministic packet marking (DPM). The implementation and evaluation demonstrates that the FDPM needs moderately a small number of packets to complete the traceback process and requires little computation work; therefore this scheme is powerful to trace the IP packets. It can be applied in many security systems, such as DDoS defense systems, intrusion detection systems (IDS), forensic systems, and so on.
Keywords :
IP networks; telecommunication security; telecommunication services; IP packets; IP traceback technique; deterministic packet marking; distributed denial of service attack; flexible deterministic packet marking; link testing; logging; messaging; probabilistic packet marking; security systems; Availability; Computer crime; Counterfeiting; Debugging; Forensics; Information security; Information technology; Intrusion detection; Power system security; Testing; DDoS; Flexible Deterministic Packet Marking; IP traceback; hash function; security;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
IP Operations and Management, 2004. Proceedings IEEE Workshop on
Print_ISBN :
0-7803-8836-4
Type :
conf
DOI :
10.1109/IPOM.2004.1547624
Filename :
1547624
Link To Document :
بازگشت