Title :
Fast Traceback against Large-Scale DDoS Attack in High-Speed Internet
Author :
Zhou, Zaihong ; Qian, Biwei ; Tian, Xiaomei ; Xie, Dongqing
Author_Institution :
Sch. of Comput. & Commun., Hunan Univ., Changsha, China
Abstract :
This paper describes a novel DDoS traceback scheme. It aims at the disadvantages of the current schemes, which can not traceback the large-scale DDoS attack with the increasing false positive rate, or which can not traceback the DDoS attack fast from the large number of packets required for reconstruction, or which can not apply in the high-speed Internet because of the high overhead of network and router etc. The proposed scheme maps k hash digests of the router´s IP into an m-bit Bloom Filter array. Then the m-bit Bloom Filter array is probabilistically written into the IP header of the passing packet or deterministically accumulated with the marking information in the IP header of the marked packet. If the Bloom Filter array in the marking information is full, the marking information is probabilistically written into another packet with the same source address and same destination address. This scheme has several advantages low false positive rate; fewer packets to reconstruct the attack path; and low computation overhead and storage overhead at the router. It implements the local traceback fast under large-scale DDOS attack in high-speed Internet.
Keywords :
Internet; cryptography; file organisation; IP header; high-speed Internet; large-scale DDoS attack; m-bit bloom filter array; router IP; scheme maps k hash; Computer crime; Computer science; Data compression; Data structures; IP networks; Information filtering; Information filters; Internet; Large-scale systems; Software;
Conference_Titel :
Computational Intelligence and Software Engineering, 2009. CiSE 2009. International Conference on
Conference_Location :
Wuhan
Print_ISBN :
978-1-4244-4507-3
Electronic_ISBN :
978-1-4244-4507-3
DOI :
10.1109/CISE.2009.5363316