DocumentCode
414953
Title
Scalable packet digesting schemes for IP traceback
Author
Lee, Tsern-Huei ; Wu, Wei-Kai ; Huang, Tze-Yau William
Author_Institution
Dept. of Commun., Nat. Chiao Tung Univ., Taiwan
Volume
2
fYear
2004
fDate
20-24 June 2004
Firstpage
1008
Abstract
Identifying the sources of an attack is an important task in the Internet security area. An attack could consist of a large number of packet streams generated by many compromised slaves that consume resources associated with various network elements to deny normal services or a few offending packets to disable a system. Several techniques based on probabilistic samples of transit packets have been developed, to determine the sources of large packet flows. It seems that logging of packet digests is necessary for traceback of an individual packet. A clever technique based on Bloom filters has recently been proposed to generate the audit trails for each individual packet within the network. The scheme is effective. However, the storage requirement is approximately 0.5% of the link capacity, which becomes a problem as link capacity increases. In this paper, we propose packet digesting schemes for flows and sets of packets sharing the same source and destination addresses. Compared with the individual packet digesting scheme, these schemes can achieve similar goals and are much more scalable. Simulations with real Internet traffic show that the storage requirements of our proposed schemes are one to two orders of magnitude lower.
Keywords
IP networks; Internet; security of data; telecommunication links; telecommunication security; telecommunication traffic; Bloom filters; IP traceback; Internet security; Internet traffic; destination addresses; distributed denial of service; link capacity; packet digesting schemes; packet sharing; packet streams; source addresses; transit packets; Communication system security; Computer crime; Computer science; Computer security; Electronic mail; Filtering; IP networks; Internet; Protocols; Telecommunication traffic;
fLanguage
English
Publisher
ieee
Conference_Titel
Communications, 2004 IEEE International Conference on
Print_ISBN
0-7803-8533-0
Type
conf
DOI
10.1109/ICC.2004.1312653
Filename
1312653
Link To Document