A novel traceback method of dynamic probabilistic packet marking with multi-tag
called iTrace-DPPM
is proposed to solve the problem that DoS attacks are difficult to defend in the field of network security. True source addresses of direct and reflective DoS attacks based on internet control message protocol(ICMP)are identified with the proposed method. The method firstly calculates the number of routing tags stored in an ICMP packet with considering the size of data segment and the threshold value of maximum transmission unit. When a router is prepared to mark a packet
the distance from the generating node of the packet is deduced according to the time to live
the marking probability is set as the reciprocal of distance
and the probabilistic packet marking algorithm is further performed for one time at each tag field of one packet independently. Finally
the victim host reconstructs the complete forwarding paths from the received routing mark information and determines the true source host who launches DoS attacks. A comparison with existing dynamic probabilistic packet marking approach shows that the proposed iTrace-DPPM has the following three advantages: less attacking packets needed in reconstructing attack paths
support of partial deployment
and no extra network load. A series of simulations under NS2 show that the number of attacking packets needed by the iTrace-DPPM is reduced to the reciprocal of the number of routing tags of the traditional DPPM.
关键词
Keywords
references
ALOMARI E, MANICKAM S, GUPTA B B, et al. Botnet-based distributed denial of service(DDoS)attacks on web servers: classification and art [J]. International Journal of Computer Applications, 2012, 49(7): 24-32.
PENG Tao, LECKIE C, RAMAMOHANARAO K. Survey of network-based defense mechanisms countering the DoS and DDoS problem [J]. ACM Computing Surveys, 2007, 39(1): 1-42.
VINCENT S, RAJA J I J. A survey of IP traceback mechanisms to overcome denial-of-service attacks [C]∥Proceedings of the 12th International Conference on Networking, VLSI and Signal Processing. Stevens Point, WI, USA: World Scientific and Engineering Academy and Society, 2010: 93-98.
MALLIGA S, TAMILARASI A. A hybrid scheme using packet marking and logging for IP traceback [J]. International Journal of Internet Protocol Technology, 2010, 5(1): 81-91.
BELENKY A, ANSARI N. On IP traceback [J]. IEEE Communication Magazine, 2003, 41(7): 142-153.
SANTHANAM L, KUMAR A, AGRAWAL D P. Taxonomy of IP traceback [J]. Journal of Information Assurance and Security, 2006, 1(2): 79-94.
JIANG Hua, LI Mingzhen, WANG Xin. A PPM probabilistic packet marking improving scheme [J]. Journal of Shandong University: Natural Science, 2011, 46(9): 85-88.
LIU J, LEE Z J, CHUNG Y C. Dynamic probabilistic packet marking for efficient IP traceback [J]. Computer Networks, 2007, 51(3): 866-882.
BELLOVIN S M. ICMP traceback messages [EB/OL].(2003-02-05)[2013-03-10]. http:∥tools.ietf.org/html/draft-ietf-itrace-04.
GUERID H, SERHROUCHNI A, ACHEMLAL M, et al. A novel traceback approach for direct and reflected ICMP attacks [C]∥Proceedings of 2011 Conference on Network and Information Systems Security(SAR-SSI). Piscataway, NJ, USA: IEEE, 2011: 1-5.
ETHAN K B. Practical reverse traceroute [EB/OL].(2009-01-09)[2013-01-10]. http:∥www.nanog.org/meetings/nanog45/presentations/Tuesday/Katz_rever