Practical network support for IP traceback
Top Cited Papers
- 28 August 2000
- journal article
- Published by Association for Computing Machinery (ACM) in ACM SIGCOMM Computer Communication Review
- Vol. 30 (4) , 295-306
- https://doi.org/10.1145/347057.347560
Abstract
This paper describes a technique for tracing anonymous packet flooding attacks in the Internet back towards their source. This work is motivated by the increased frequency and sophistication of denial-of-service attacks and by the difficulty in tracing packets with incorrect, or ``spoofed'', source addresses. In this paper we describe a general purpose traceback mechanism based on probabilistic packet marking in the network. Our approach allows a victim to identify the network path(s) traversed by attack traffic without requiring interactive operational support from Internet Service Providers (ISPs). Moreover, this traceback can be performed ``post-mortem'' -- after an attack has completed. We present an implementation of this technology that is incrementally deployable, (mostly) backwards compatible and can be efficiently implemented using conventional technology.Keywords
This publication has 11 references indexed in Scilit:
- Heuristics for Internet map discoveryPublished by Institute of Electrical and Electronics Engineers (IEEE) ,2002
- Dynamic distance maps of the InternetPublished by Institute of Electrical and Electronics Engineers (IEEE) ,2002
- Providing guaranteed services without per flow managementPublished by Association for Computing Machinery (ACM) ,1999
- A review of port scanning techniquesACM SIGCOMM Computer Communication Review, 1999
- Anonymous connections and onion routingIEEE Journal on Selected Areas in Communications, 1998
- End-to-end routing behavior in the InternetIEEE/ACM Transactions on Networking, 1997
- Requirements for IP Version 4 RoutersPublished by RFC Editor ,1995
- Security problems in the TCP/IP protocol suiteACM SIGCOMM Computer Communication Review, 1989
- Fragmentation considered harmfulPublished by Association for Computing Machinery (ACM) ,1987
- Internet ProtocolPublished by RFC Editor ,1981