CQUniversity
Browse

Flexible deterministic packet marking : an IP traceback system to find the real source of attacks

Download (2.96 MB)
journal contribution
posted on 2017-12-06, 00:00 authored by Yang Xiang, W Zhou, M Guo
Internet Protocol (IP) traceback is the enabling technology to control Internet crime. In this paper we present a novel and practical IP traceback system called Flexible Deterministic Packet Marking (FDPM) which provides a defense system with the ability to find out the real sources of attacking packets that traverse through the network. While a number of other traceback schemes exist, FDPM provides innovative features to trace the source of IP packets and can obtain better tracing capability than others. In particular, FDPM adopts a flexible mark length strategy to make it compatible to different network environments; it also adaptively changes its marking rate according to the load of the participating router by a flexible flow-based marking scheme. Evaluations on both simulation and real system implementation demonstrate that FDPM requires a moderately small number of packets to complete the traceback process; add little additional load to routers and can trace a large number of sources in one traceback process with low false positive rates. The built-in overload prevention mechanism makes this system capable of achieving a satisfactory traceback result even when the router is heavily loaded. The motivation of this traceback system is from DDoS defense. It has been used to not only trace DDoS attacking packets but also enhance filtering attacking traffic. It has wide appllications for other security systems.

Funding

Category 1 - Australian Competitive Grants (this includes ARC, NHMRC)

History

Volume

20

Issue

4

Start Page

567

End Page

580

Number of Pages

14

ISSN

1045-9219

Location

New York

Publisher

IEEE Computer Society

Language

en-aus

Peer Reviewed

  • Yes

Open Access

  • No

External Author Affiliations

Centre for Intelligent and Networked Systems (CINS); Deakin University; Institute for Resource Industries and Sustainability (IRIS); Shanghai jiao tong da xue;

Era Eligible

  • Yes

Journal

IEEE transactions on parallel and distributed systems.

Usage metrics

    CQUniversity

    Exports

    RefWorks
    BibTeX
    Ref. manager
    Endnote
    DataCite
    NLM
    DC