Authors:
Ping Yan
and
Moon Chuen Lee
Affiliation:
The Chinese University of Hong Kong, China
Keyword(s):
DoS attacks, IP traceback, probabilistic packet marking, inter-domain marking, source router marking, attack graph reconstruction.
Related
Ontology
Subjects/Areas/Topics:
Information and Systems Security
;
Network Security
Abstract:
Denial of Service attacks have become one of the most serious threats to the Internet community. An effec-tive means to defend against such attacks is to locate the attack source(s) and to isolate it from the rest of the network. This paper proposes an adaptive packet marking scheme for IP traceback, which supports two types of marking, namely source router id marking and domain id marking. For each packet traversing, we let the border routers perform probabilistic router id marking if this packet enters the network for the first time, or perform probabilistic domain id marking if the packet is forwarded from another domain. After col-lecting sufficient packets, the victim reconstructs the attack graph, by which we keep track of the interme-diate domains traversed by attack packets instead of individual routers within a domain; however, the source routers serving as ingress points of attack traffic are identified at the same time. Simulation results show that the proposed marking sch
eme outperforms other IP traceback methods as it requires fewer pack-ets for attack paths reconstruction, and can handle large number of attack sources effectively; and the false positives produced are significantly low. Further, it does not generate additional traffic.
(More)