|
ABSTRACT
The design of the IP protocol makes it difficult to reliably identify the originator of an IP packet. Even in the absence of any deliberate attempt to disguise a packet's origin, widespread packet forwarding techniques such as NAT and encapsulation may obscure the packet's true source. Techniques have been developed to determine the source of large packet flows, but, to date, no system has been presented to track individual packets in an efficient, scalable fashion. We present a hash-based technique for IP traceback that generates audit trails for traffic within the network, and can trace the origin of a single IP packet delivered by the network in the recent past. We demonstrate that the system is effective, space efficient (requiring approximately 0.5% of the link capacity per unit time in storage), and implementable in current or next-generation routing hardware. We present both analytic and simulation results showing the system's effectiveness.
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
| |
1
|
Microsoft Corporation. Stop 0A in tcpip.sys when receiving out of band (OOB) data. {Online}. Available: http://support.microsoft.com/support/kb/articles/Q143/4/78.asp
|
| |
2
|
P. Ferguson and D. Senie, "Network ingress filtering: Defeating denial of service attacks which employ IP source address spoofing," IETF, RFC 2267, Jan. 1998.
|
 |
3
|
|
| |
4
|
|
| |
5
|
C. Shannon, D. Moore, and K. Claffy, "Characteristics of fragmented IP traffic on Internet links," presented at the RIPE Workshop Passive and Active Measurements, Amsterdam, The Netherlands, Apr. 2001.
|
 |
6
|
|
| |
7
|
F. Baker, "Requirements for IP version 4 routers," IETF, RFC 1812, June 1995.
|
| |
8
|
S. McCreary and K. Claffy, "Trends in wide area IP traffic patterns: A view from Ames Internet exchange," presented at the ITC Specialist Seminar IP Traffic Modeling, Measurement and Management, Monterey, CA, Sept. 2000.
|
| |
9
|
|
| |
10
|
|
| |
11
|
S. M. Bellovin, M. Leech, and T. Taylor, "ICMP traceback messages," IETF, Internet Draft, draft-ietf-itrace-01.txt (work in progress), Oct. 2001.
|
| |
12
|
D. X. Song and A. Perrig, "Advanced and authenticated marking schemes for IP traceback," in Proc. IEEE Infocom'01, Apr. 2001, pp. 878-886.
|
| |
13
|
A. Mankin, D. Massey, C.-L. Wu, S. F. Wu, and L. Zhang, "On design and evaluation of 'intention-driven' ICMP traceback," in Proc. IEEE Int. Conf. Computer Communications and Networks, Oct. 2001, pp. 159-165.
|
| |
14
|
G. Sager. "Security fun with OCxmon and cflowd", presented at Internet 2 Working Group Meeting. {Online}. Available: http://www.caida.org/projects/NGI/content/security/1198.
|
| |
15
|
D. Schnackenberg, K. Djahandari, and D. Sterne, "Infrastructure for intrusion detection and response," in Proc. First DARPA Information Survivability Conf. Exposition, vol. 2, Jan. 2000, pp. 1003-1011.
|
| |
16
|
R. Stone, "CenterTrack: An IP overlay network for tracking DoS floods," in Proc. USENIX Security Symp., July 2000, pp. 199-212.
|
 |
17
|
N. G. Duffield , M. Grossglauser, Trajectory sampling for direct traffic observation, Proceedings of the conference on Applications, Technologies, Architectures, and Protocols for Computer Communication, p.271-282, August 28-September 01, 2000, Stockholm, Sweden
|
| |
18
|
|
| |
19
|
L. Carter and M. Wegman, "Universal classes of hash functions," J. Comput. Syst. Sci., vol. 18, no. 2, pp. 143-154, 1979.
|
| |
20
|
|
| |
21
|
|
| |
22
|
|
| |
23
|
J. Postel, "Internet protocol," IETF, RFC 791, Sept. 1981.
|
| |
24
|
____, "Internet control message protocol," IETF, RFC 792, Sept. 1981.
|
| |
25
|
R. Rivest, "The MD5 message-digest algorithm," IETF, RFC 1321, Apr. 1992.
|
| |
26
|
L. A. Sanchez, W. C. Milliken, A. C. Snoeren, F. Tchakountio, C. E. Jones, S. T. Kent, C. Partridge, and W. T. Strayer, "Hardware support for a hash-based IP traceback," in Proc. Second DARPA Information Survivability Conf. Exposition, vol. 2, June 2001, pp. 146-152.
|
| |
27
|
C. Fraleigh, C. Diot, B. Lyles, S. Moon, P. Owezarski, D. Papagiannaki, and F. Tobagi, "Design and deployment of a passive monitoring infrastructure," presented at the RIPE Workshop Passive and Active Measurements, Amsterdam, The Netherlands, Apr. 2001.
|
| |
28
|
|
CITED BY 46
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Min Cai , Jianping Pan , Yu-Kwong Kwok , Kai Hwang, Fast and accurate traffic matrix measurement using adaptive cardinality counting, Proceeding of the 2005 ACM SIGCOMM workshop on Mining network data, August 26-26, 2005, Philadelphia, Pennsylvania, USA
|
|
|
|
|
|
Chun-Hsin Wang , Chang-Wu Yu , Chiu-Kuo Liang , Kun-Min Yu , Wen Ouyang , Ching-Hsien Hsu , Yu-Guang Chen, Tracers placement for IP traceback against DDoS attacks, Proceeding of the 2006 international conference on Communications and mobile computing, July 03-06, 2006, Vancouver, British Columbia, Canada
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Patrick Verkaik , Oliver Spatscheck , Jacobus Van der Merwe , Alex C. Snoeren, PRIMED: community-of-interest-based DDoS mitigation, Proceedings of the 2006 SIGCOMM workshop on Large-scale attack defense, p.147-154, September 11-15, 2006, Pisa, Italy
|
|
|
|
|
|
|
|
|
|
|
|
Jerry Chou , Bill Lin , Subhabrata Sen , Oliver Spatscheck, Proactive surge protection: a defense mechanism for bandwidth-based attacks, Proceedings of the 17th conference on Security symposium, p.123-138, July 28-August 01, 2008, San Jose, CA
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Jun Li , Jelena Mirkovic , Toby Ehrenkranz , Mengqiu Wang , Peter Reiher , Lixia Zhang, Learning the valid incoming direction of IP packets, Computer Networks: The International Journal of Computer and Telecommunications Networking, v.52 n.2, p.399-417, February, 2008
|
|
|
Edmund L. Wong , Praveen Balasubramanian , Lorenzo Alvisi , Mohamed G. Gouda , Vitaly Shmatikov, Truth in advertising: lightweight verification of route integrity, Proceedings of the twenty-sixth annual ACM symposium on Principles of distributed computing, August 12-15, 2007, Portland, Oregon, USA
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Hiroshi Tsunoda , Kohei Ohta , Atsunori Yamamoto , Nirwan Ansari , Yuji Waizumi , Yoshiaki Nemoto, Detecting DRDoS attacks by a simple response packet confirmation mechanism, Computer Communications, v.31 n.14, p.3299-3306, September, 2008
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|