1. 西安交通大学制造系统工程国家重点实验室,西安,710049
2. 上海交通大学信息安全工程学院,上海,200240
网络首发:2013-10-10,
纸质出版:2013
移动端阅览
陈秀真 1, 2, 李生红 3, 等. 面向拒绝服务攻击的多标签IP返回追踪新方法[J]. 西安交通大学学报, 2013,47(10):13-17.
A New Approach of IP Traceback with Multiple Marking Tags for DoS Attacks[J]. 2013, 47(10): 13-17.
陈秀真 1, 2, 李生红 3, 等. 面向拒绝服务攻击的多标签IP返回追踪新方法[J]. 西安交通大学学报, 2013,47(10):13-17. DOI: 10.7652/xjtuxb201310003.
A New Approach of IP Traceback with Multiple Marking Tags for DoS Attacks[J]. 2013, 47(10): 13-17. DOI: 10.7652/xjtuxb201310003.
针对网络安全中拒绝服务攻击难以防御的特点
提出面向拒绝服务攻击的多标签IP返回追踪方法(iTrace-DPPM)
用以识别基于互联网控制报文协议(ICMP)的直接和反射式拒绝服务攻击的真实源地址。该方法首先结合ICMP数据段大小及最大传输单元阀值
计算单一ICMP数据报文可携带的路由标记数
再根据数据包的幸存时间推断路由器与攻击源头的距离
将路由器的标记概率设定为距离的倒数
并针对每个标记域独立地执行概率标记算法
最后受害目标根据接收的标记信息
实现转发路径的重构及源头识别。与已有的动态概率包标记方法相比
iTrace-DPPM方法具有路径重构所需数据包少、支持部分部署及无额外负载的优点。NS2环境下的模拟实验结果证实
路径重构所需的攻击包数降为DPPM方法的路由标记数的倒数。
A novel traceback method of dynamic probabilistic packet marking with multi-tag
called iTrace-DPPM
is proposed to solve the problem that DoS attacks are difficult to defend in the field of network security. True source addresses of direct and reflective DoS attacks based on internet control message protocol(ICMP)are identified with the proposed method. The method firstly calculates the number of routing tags stored in an ICMP packet with considering the size of data segment and the threshold value of maximum transmission unit. When a router is prepared to mark a packet
the distance from the generating node of the packet is deduced according to the time to live
the marking probability is set as the reciprocal of distance
and the probabilistic packet marking algorithm is further performed for one time at each tag field of one packet independently. Finally
the victim host reconstructs the complete forwarding paths from the received routing mark information and determines the true source host who launches DoS attacks. A comparison with existing dynamic probabilistic packet marking approach shows that the proposed iTrace-DPPM has the following three advantages: less attacking packets needed in reconstructing attack paths
support of partial deployment
and no extra network load. A series of simulations under NS2 show that the number of attacking packets needed by the iTrace-DPPM is reduced to the reciprocal of the number of routing tags of the traditional DPPM.
ALOMARI E, MANICKAM S, GUPTA B B, et al. Botnet-based distributed denial of service(DDoS)attacks on web servers: classification and art [J]. International Journal of Computer Applications, 2012, 49(7): 24-32.
PENG Tao, LECKIE C, RAMAMOHANARAO K. Survey of network-based defense mechanisms countering the DoS and DDoS problem [J]. ACM Computing Surveys, 2007, 39(1): 1-42.
VINCENT S, RAJA J I J. A survey of IP traceback mechanisms to overcome denial-of-service attacks [C]∥Proceedings of the 12th International Conference on Networking, VLSI and Signal Processing. Stevens Point, WI, USA: World Scientific and Engineering Academy and Society, 2010: 93-98.
MALLIGA S, TAMILARASI A. A hybrid scheme using packet marking and logging for IP traceback [J]. International Journal of Internet Protocol Technology, 2010, 5(1): 81-91.
BELENKY A, ANSARI N. On IP traceback [J]. IEEE Communication Magazine, 2003, 41(7): 142-153.
SANTHANAM L, KUMAR A, AGRAWAL D P. Taxonomy of IP traceback [J]. Journal of Information Assurance and Security, 2006, 1(2): 79-94.
蒋华, 李明珍, 王鑫. 一种基于概率包标记的PPM算法改进方案 [J]. 山东大学学报:理学版, 2011, 46(9): 85-88.
JIANG Hua, LI Mingzhen, WANG Xin. A PPM probabilistic packet marking improving scheme [J]. Journal of Shandong University: Natural Science, 2011, 46(9): 85-88.
LIU J, LEE Z J, CHUNG Y C. Dynamic probabilistic packet marking for efficient IP traceback [J]. Computer Networks, 2007, 51(3): 866-882.
BELLOVIN S M. ICMP traceback messages [EB/OL].(2003-02-05)[2013-03-10]. http:∥tools.ietf.org/html/draft-ietf-itrace-04.
GUERID H, SERHROUCHNI A, ACHEMLAL M, et al. A novel traceback approach for direct and reflected ICMP attacks [C]∥Proceedings of 2011 Conference on Network and Information Systems Security(SAR-SSI). Piscataway, NJ, USA: IEEE, 2011: 1-5.
ETHAN K B. Practical reverse traceroute [EB/OL].(2009-01-09)[2013-01-10]. http:∥www.nanog.org/meetings/nanog45/presentations/Tuesday/Katz_rever
setraceroute_N45.pdf.
0
浏览量
4
下载量
0
CSCD
关联资源
相关文章
相关作者
相关机构
京公网安备11010802024621