首页> 外文期刊>Cluster computing >IP traceback with sparsely-tagged fragment marking scheme under massively multiple attack paths
【24h】

IP traceback with sparsely-tagged fragment marking scheme under massively multiple attack paths

机译:大规模多重攻击路径下具有稀疏标记片段标记方案的IP回溯

获取原文
获取原文并翻译 | 示例
           

摘要

IP traceback is known to be one of the most effective measures to deter Internet attacks. Various techniques for IP traceback have been suggested. Among them, we focus on Probabilistic Packet Marking scheme (PPM) with tagging. We believe PPM is more advantageous than others because it does not generate additional network traffic and requires minimal protocol change. However, three parameters need to be optimized to make PPM practical under massively multiple attack paths: the number of packets to collect, the number of fragment combinations to recover the IP addresses, and the false positive error rate. Tagging is an effective way to reduce the number of combinations but it increases the false positive error rates when the number of routers in the attack paths grows. Other PPM-related techniques suggested in the past have similar problems. They improve one or two parameters at the expense of others, or they require additional data structures such as an upstream router map. In this paper, we propose a method that optimizes the three parameters at the same time and recovers original IPs quickly and correctly even in the presence of massive multiple attack paths. Our method does not need either a combinatorial process to recover IPs or additional information such as an upstream router map. Our result shows that our method recovers 95% of the original IPs correctly with no fragment combinations and with zero false positives. It needs to collect only 8N packets per router where N is the number of routers involved in the attack paths.
机译:已知IP跟踪是阻止Internet攻击的最有效措施之一。已经提出了各种用于IP回溯的技术。其中,我们重点关注带标记的概率数据包标记方案(PPM)。我们认为PPM比其他方法更具优势,因为它不会产生额外的网络流量,并且需要最少的协议更改。但是,需要优化三个​​参数以使PPM在大规模的多个攻击路径下切实可行:要收集的数据包数量,用于恢复IP地址的片段组合数量以及误报率。标记是减少组合数量的有效方法,但是当攻击路径中的路由器数量增加时,它会增加误报率。过去建议的其他与PPM相关的技术也存在类似的问题。它们以牺牲其他参数为代价来改善一个或两个参数,或者它们需要其他数据结构,例如上游路由器映射。在本文中,我们提出了一种方法,该方法可以同时优化这三个参数,即使在存在大量多重攻击路径的情况下,也可以快速,正确地恢复原始IP。我们的方法不需要恢复IP的组合过程,也不需要诸如上游路由器映射之类的其他信息。我们的结果表明,我们的方法正确地恢复了95%的原始IP,没有片段组合且误报为零。每个路由器仅需要收集8N个数据包,其中N是攻击路径中涉及的路由器数量。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号