【24h】

A prediction based approach to IP traceback

机译:基于预测的IP追溯方法

获取原文

摘要

Sources of a Distributed Denial of Service (DDoS) attack can be identified by the traffic they generate using the IP traceback technique. Because of its relevance, the Probabilistic Packet Marking (PPM) schemes for IP traceback is an intensively researched field. In these schemes, routers are given the extra function of randomly selecting packets from those that go through them, to embed their address information in those selected packets. During or after the attack, the paths that were traversed by the attack traffic can be identified based on the router information in the marked packets. Since these schemes require a large number of received packets to trace an attacker successfully, they usually demand a high time and space complexity to trace many attackers as is the case in DDoS attacks. This is partly because the marking scheme allows remarking, where routers can overwrite previous marking information in a selected packet, which leads to data loss. We present the Prediction Based Scheme (PBS), which is an addition to the PPM schemes for IP tracetrack. The proposed approach consists of two parts: (a) a marking scheme, that reduces the number of packets required to trace a DoS attacker and (b) an extension to a traceback algorithm, whose main feature is to return a complete attack graph with fewer received packets than the traditional algorithm. The proposed marking scheme alleviates the problem of data loss by ensuring previous marking information is not overwritten. Additionally, the proposed traceback algorithm uses graphs built using legitimate traffic to predict the path taken by attack traffic. Results show that the marking scheme in PBS, compared to PPM, ensures that traceback is possible with about 54% as many total packets to achieve complete attack path construction, while the traceback algorithm takes about 33% as many marked packets.
机译:分布式拒绝服务(DDoS)攻击的来源可以通过使用IP跟踪技术生成的流量来识别。由于其相关性,用于IP追溯的概率数据包标记(PPM)方案是一个深入研究的领域。在这些方案中,为路由器提供了额外的功能,即从经过它们的路由器中随机选择数据包,以将其地址信息嵌入那些选定的数据包中。在攻击期间或之后,可以根据标记数据包中的路由器信息来确定攻击流量所经过的路径。由于这些方案需要大量接收到的数据包才能成功跟踪攻击者,因此通常需要很高的时间和空间复杂度来跟踪许多攻击者,就像DDoS攻击一样。部分原因是标记方案允许重新标记,路由器可以覆盖选定数据包中的先前标记信息,从而导致数据丢失。我们提出了基于预测的方案(PBS),它是IP跟踪的PPM方案的补充。提议的方法包括两部分:(a)标记方案,减少跟踪DoS攻击者所需的数据包数量;(b)追溯算法的扩展,其主要特征是返回具有更少内容的完整攻击图接收到的数据包比传统算法要多。所提出的标记方案通过确保不覆盖先前的标记信息来减轻数据丢失的问题。此外,提出的追溯算法使用使用合​​法流量构建的图来预测攻击流量所采用的路径。结果表明,与PPM相比,PBS中的标记方案可确保以约54%的总数据包进行回溯以实现完整的攻击路径构造,而回溯算法则可使用约33%的标记数据包。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号