• DocumentCode
    395592
  • Title

    A path information caching and aggregation approach to traffic source identification

  • Author

    Hsu, Fu-Hau ; Chiueh, Tzi-cker

  • Author_Institution
    Dept. of Comput. Sci., State Univ. of New York, Stony Brook, NY, USA
  • fYear
    2003
  • fDate
    19-22 May 2003
  • Firstpage
    332
  • Lastpage
    339
  • Abstract
    Probabilistic packet marking (PPM) is a technique designed to identify packet traffic sources with low storage and processing overhead on network routers. In most previous PPM approaches, individual path messages carry only partial path information. These methods are susceptible to "path falsification" attacks, which greatly reduce their effectiveness. This work proposes a path-falsification-attack free PPM algorithm called Path Information Caching and Aggregation (PICA) that records paths of packet streams in fix-length path messages, thus eliminating the need of path reconstruction at the receiver end. Besides, by using a router\´s forwarding table to decompose packet volume, this semi-stateful method is more accurate in traffic volume report. It also supports both a packet rate-based path message generation algorithm and a redundant path message suppression mechanism to further eliminate path messages with the same destination. Finally, PICA protects PICA routers from being attacked by faked path messages. We have performed a trace-driven simulation study on the proposed PICA algorithm and compared its effectiveness with IETF\´s iTrace scheme by varying the sampling probability, the number of attack sources, and attack traffic rate. Compared to iTrace, the PICA algorithm reduces the total number of path messages required by a factor of more than 2, while reporting traffic volume more accurately.
  • Keywords
    cache storage; message authentication; telecommunication network routing; telecommunication traffic; PICA network routers; lETFs iTrace scheme; packet sampling; packet traffic source identification; path information caching and aggregation; path message generation algorithm; probabilistic packet marking; probability; redundant path message suppression mechanism; Computer crime; Computer science; IP networks; Master-slave; Network servers; Protection; Sampling methods; Telecommunication traffic; Traffic control; Web server;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Distributed Computing Systems, 2003. Proceedings. 23rd International Conference on
  • ISSN
    1063-6927
  • Print_ISBN
    0-7695-1920-2
  • Type

    conf

  • DOI
    10.1109/ICDCS.2003.1203482
  • Filename
    1203482