2008Unpublished venueRequires access

A Novel Two-Step Traceback Scheme for DDoS Attacks

Zhaoyang Qu, Chunfeng Huang, Ningning Liu

Open publisher page 9 citations

Abstract

The defense against Distributed Denial of Service (DDoS) attacks is one of the primary concerns on the Internet today. IP spoofing makes it difficult for the victim to determine the packet's true origin. There is a need for a mechanism that could rapidly trace back to the attacks' origins for the victim. This paper presents a two-step traceback scheme to track DDoS attack source by dividing the tracing process into two steps. In the first step, packet marking method based on autonomous system (ASPMM) is adopted to determine the attack-originating autonomous system (AS). In the second step, non-repeated probabilistic packet marking (NRPPM) is used to identify the exact origin of the attacks in the specific AS. Compared with previous algorithms, the two-step traceback scheme has the benefits of low bandwidth consumption, quick convergence speed, light computational overhead of address recombination, it can decrease the number of packets the path reconstruction needs, and improve the efficiency of path reconstruction, hence making it possible to trace the DDoS attack source rapidly.

About this research paper

What this paper is about

The defense against Distributed Denial of Service (DDoS) attacks is one of the primary concerns on the Internet today. IP spoofing makes it difficult for the victim to determine the packet's true origin. There is a need for a mechanism that could rapidly trace back to the attacks' origins for the victim. This paper presents a two-step traceback scheme to track DDoS attack source by dividing the tracing process into two steps. In the first step, packet marking method based on autonomous system (ASPMM) is adopted to determine the attack-originating autonomous system (AS). In the second step, non-repeated probabilistic packet marking (NRPPM) is used to identify the exact origin of the attacks in the specific AS. Compared with previous algorithms, the two-step traceback scheme has the benefits of low bandwidth consumption, quick convergence speed, light computational overhead of address recombination, it can decrease the number of packets the path reconstruction needs, and improve the efficiency of path reconstruction, hence making it possible to trace the DDoS attack source rapidly.

Why it matters

OpenAlex reports 9 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

The defense against Distributed Denial of Service (DDoS) attacks is one of the primary concerns on the Internet today. IP spoofing makes it difficult for the victim to determine the packet's true origin. There is a need for a mechanism that could rapidly trace back to the attacks' origins for the victim. This paper presents a two-step traceback scheme to track DDoS attack source by dividing the tracing process into two steps. In the first step, packet marking method based on autonomous system (ASPMM) is adopted to determine the attack-originating autonomous system (AS). In the second step, non-repeated probabilistic packet marking (NRPPM) is used to identify the exact origin of the attacks in the specific AS. Compared with previous algorithms, the two-step traceback scheme has the benefits of low bandwidth consumption, quick convergence speed, light computational overhead of address recombination, it can decrease the number of packets the path reconstruction needs, and improve the efficiency of path reconstruction, hence making it possible to trace the DDoS attack source rapidly.

Key concepts: IP traceback, Denial-of-service attack, Computer science, Network packet, Computer network, Application layer DDoS attack, Trinoo, IP address spoofing

Related papers

Back to paper searchBrowse research topicsOriginal source
A Novel Two-Step Traceback Scheme for DDoS Attacks — Research Paper | ScholarLens