2008Unpublished venueRequires access

Detection of Spoofing Attacks Using Intrusive Filters For DDoS

V. Shyamaladevi, R. S. D. Wahidabanu

Open publisher page 4 citations

Abstract

Internet hosts are threatened by large-scale Distributed Denialof-Service (DDoS) attacks. The Path Identification DDoS defense scheme has recently been proposed as a deterministic packet marking scheme that allows a DDoS victim to filter out attack packets on a per packet basis with high accuracy after only a few attack packets are received. This paper proposes the Stack Path identification marking, a new packet marking scheme based on path identification, and new filtering mechanisms. The Stack Path Identification marking scheme consists of two new marking methods that substantially improve Path identifier’s incremental deployment performance i.e., Stack-based marking and Write-ahead marking. The proposed scheme almost completely eliminates the effect of a few legacy routers on a path, and performs better than the original Path identification scheme in a sparse deployment of path identifier enabled routers. For the filtering mechanism, derive an optimal threshold strategy for filtering with the Path identification marking. The system develops the path identification IP filter, which can be used to detect IP spoofing attacks with just a single attack packet. Finally, evaluate the Stack path identification’s compatibility with IP Fragmentation, applicability in an IPv6 environment, and several other important issues relating to potential deployment of Stack path identification.

About this research paper

What this paper is about

Internet hosts are threatened by large-scale Distributed Denialof-Service (DDoS) attacks. The Path Identification DDoS defense scheme has recently been proposed as a deterministic packet marking scheme that allows a DDoS victim to filter out attack packets on a per packet basis with high accuracy after only a few attack packets are received. This paper proposes the Stack Path identification marking, a new packet marking scheme based on path identification, and new filtering mechanisms. The Stack Path Identification marking scheme consists of two new marking methods that substantially improve Path identifier’s incremental deployment performance i.e., Stack-based marking and Write-ahead marking. The proposed scheme almost completely eliminates the effect of a few legacy routers on a path, and performs better than the original Path identification scheme in a sparse deployment of path identifier enabled routers. For the filtering mechanism, derive an optimal threshold strategy for filtering with the Path identification marking. The system develops the path identification IP filter, which can be used to detect IP spoofing attacks with just a single attack packet. Finally, evaluate the Stack path identification’s compatibility with IP Fragmentation, applicability in an IPv6 environment, and several other important issues relating to potential deployment of Stack path identification.

Why it matters

OpenAlex reports 4 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

Internet hosts are threatened by large-scale Distributed Denialof-Service (DDoS) attacks. The Path Identification DDoS defense scheme has recently been proposed as a deterministic packet marking scheme that allows a DDoS victim to filter out attack packets on a per packet basis with high accuracy after only a few attack packets are received. This paper proposes the Stack Path identification marking, a new packet marking scheme based on path identification, and new filtering mechanisms. The Stack Path Identification marking scheme consists of two new marking methods that substantially improve Path identifier’s incremental deployment performance i.e., Stack-based marking and Write-ahead marking. The proposed scheme almost completely eliminates the effect of a few legacy routers on a path, and performs better than the original Path identification scheme in a sparse deployment of path identifier enabled routers. For the filtering mechanism, derive an optimal threshold strategy for filtering with the Path identification marking. The system develops the path identification IP filter, which can be used to detect IP spoofing attacks with just a single attack packet. Finally, evaluate the Stack path identification’s compatibility with IP Fragmentation, applicability in an IPv6 environment, and several other important issues relating to potential deployment of Stack path identification.

Key concepts: Denial-of-service attack, Computer science, Spoofing attack, Computer network, Application layer DDoS attack, Network packet, Identifier, IP address spoofing

Related papers

Back to paper searchBrowse research topicsOriginal source
Detection of Spoofing Attacks Using Intrusive Filters For DDoS — Research Paper | ScholarLens