DocumentCode :
3035608
Title :
Advanced and authenticated marking schemes for IP traceback
Author :
Song, Dawn Xiaodong ; Perrig, Adrian
Author_Institution :
Dept. of Comput. Sci., California Univ., Berkeley, CA, USA
Volume :
2
fYear :
2001
fDate :
2001
Firstpage :
878
Abstract :
Defending against distributed denial-of-service attacks is one of the hardest security problems on the Internet today. One difficulty to thwart these attacks is to trace the source of the attacks because they often use incorrect, or spoofed IP source addresses to disguise the true origin. In this paper, we present two new schemes, the advanced marking scheme and the authenticated marking scheme, which allow the victim to trace-back the approximate origin of spoofed IP packets. Our techniques feature low network and router overhead, and support incremental deployment. In contrast to previous work, our techniques have significantly higher precision (lower false positive rate) and fewer computation overhead for the victim to reconstruct the attack paths under large scale distributed denial-of-service attacks. Furthermore the authenticated marking scheme provides efficient authentication of routers´ markings such that even a compromised router cannot forge or tamper markings from other uncompromised routers
Keywords :
Internet; message authentication; packet switching; telecommunication network routing; telecommunication security; transport protocols; IP traceback; Internet; advanced marking scheme; attack paths reconstruction; authenticated marking scheme; computation overhead; distributed denial-of-service attacks; low false positive rate; low network overhead; low router overhead; router markings authentication; security problems; spoofed IP packets; spoofed IP source addresses; Authentication; Computer crime; Computer science; Computer security; Contracts; Distributed computing; Internet; Large-scale systems; US Government agencies; Usability;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
INFOCOM 2001. Twentieth Annual Joint Conference of the IEEE Computer and Communications Societies. Proceedings. IEEE
Conference_Location :
Anchorage, AK
ISSN :
0743-166X
Print_ISBN :
0-7803-7016-3
Type :
conf
DOI :
10.1109/INFCOM.2001.916279
Filename :
916279
Link To Document :
بازگشت