• DocumentCode
    822128
  • Title

    Flexible Deterministic Packet Marking: An IP Traceback System to Find the Real Source of Attacks

  • Author

    Xiang, Yang ; Zhou, Wanlei ; Guo, Minyi

  • Author_Institution
    Centre for Intell. & Networked Syst., Central Queensland Univ., Rockhampton, QLD
  • Volume
    20
  • Issue
    4
  • fYear
    2009
  • fDate
    4/1/2009 12:00:00 AM
  • Firstpage
    567
  • Lastpage
    580
  • Abstract
    IP traceback is the enabling technology to control Internet crime. In this paper we present a novel and practical IP traceback system called Flexible Deterministic Packet Marking (FDPM) which provides a defense system with the ability to find out the real sources of attacking packets that traverse through the network. While a number of other traceback schemes exist, FDPM provides innovative features to trace the source of IP packets and can obtain better tracing capability than others. In particular, FDPM adopts a flexible mark length strategy to make it compatible to different network environments; it also adaptively changes its marking rate according to the load of the participating router by a flexible flow-based marking scheme. Evaluations on both simulation and real system implementation demonstrate that FDPM requires a moderately small number of packets to complete the traceback process; add little additional load to routers and can trace a large number of sources in one traceback process with low false positive rates. The built-in overload prevention mechanism makes this system capable of achieving a satisfactory traceback result even when the router is heavily loaded. It has been used to not only trace DDoS attacking packets but also enhance filtering attacking traffic.
  • Keywords
    IP networks; telecommunication network routing; telecommunication security; telecommunication traffic; DDoS attacking packet; IP traceback system; Internet crime control; filtering attacking traffic; flexible deterministic packet marking; router; Communication/Networking and Information Technology; Performance of Systems;
  • fLanguage
    English
  • Journal_Title
    Parallel and Distributed Systems, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    1045-9219
  • Type

    jour

  • DOI
    10.1109/TPDS.2008.132
  • Filename
    4585371