首页> 外文期刊>The international arab journal of information technology >STF-DM: A Sparsely Tagged Fragmentation with Dynamic Marking an IP Traceback Approach
【24h】

STF-DM: A Sparsely Tagged Fragmentation with Dynamic Marking an IP Traceback Approach

机译:STF-DM:具有动态标记IP追溯方法的稀疏标记的碎片

获取原文
获取原文并翻译 | 示例
           

摘要

Denial of Service (DoS) and Distributed Denial of Service (DDoS) attacks are serious threats to the Internet. The frequency of DoS and DDoS attacks is increasing day by day. Automated tools are also available that enable non-technical people to implement such attacks easily. Hence, it is not only important to prevent such attacks, but also need to trace back the attackers. Tracing back the sources of the attacks, which is known as an IP traceback problem is a hard problem because of the stateless nature of the Internet and spoofed Internet Protocol (IP) packets. Various approaches have been proposed for IP traceback. Probabilistic Packet Marking (PPM) approach incurs the minimum network and management overhead. Hence, we focus on PPM approach. Sparsely-Tagged Fragmentation Marking Scheme (S-TFMS), a PPM based approach, requires low overhead at the victim and achieve zero false-positives. However, it requires a large number of packets to recover the IP addresses. In this paper, we propose a Sparsely-Tagged Fragmentation Marking approach with dynamic marking probability. Our approach requires less number of packets than required by S-TFMS. Further, to reduce the number of packets required by victim, we extend our basic approach with the new marking format. Our extended approach requires less than one-tenth time number of packets than those in S-TFMS approach to recover the IP addresses. Our approaches recover the IP address quickly with zero false-positives in the presence of multiple attackers. We show mathematical as well as experimental analysis of our approaches.
机译:拒绝服务(DoS)和分布式拒绝服务(DDoS)攻击是对Internet的严重威胁。 DoS和DDoS攻击的频率每天都在增加。还可以使用自动化工具,使非技术人员可以轻松实施此类攻击。因此,防止此类攻击不仅很重要,而且还需要追溯攻击者。追溯攻击的来源(称为IP追溯问题)是一个难题,因为Internet和欺骗性的Internet协议(IP)数据包都是无状态的。已经提出了用于IP回溯的各种方法。概率数据包标记(PPM)方法带来了最小的网络和管理开销。因此,我们专注于PPM方法。稀疏标记碎片标记方案(S-TFMS)是一种基于PPM的方法,要求受害者的开销较低,并且假阳性为零。但是,它需要大量的数据包才能恢复IP地址。在本文中,我们提出了一种具有动态标记概率的稀疏标记片段标记方法。我们的方法所需的数据包数量少于S-TFMS所需的数据包数量。此外,为了减少受害者所需的数据包数量,我们使用新的标记格式扩展了基本方法。与S-TFMS方法相比,我们的扩展方法所需的数据包数量少于S-TFMS方法的十分之一。在存在多个攻击者的情况下,我们的方法以零误报迅速恢复IP地址。我们展示了我们方法的数学和实验分析。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号