Single-packet IP traceback
Top Cited Papers
- 1 December 2002
- journal article
- Published by Institute of Electrical and Electronics Engineers (IEEE) in IEEE/ACM Transactions on Networking
- Vol. 10 (6) , 721-734
- https://doi.org/10.1109/tnet.2002.804827
Abstract
The design of the IP protocol makes it difficult to reliably identify the originator of an IP packet. Even in the absence of any deliberate attempt to disguise a packet's origin, widespread packet forwarding techniques such as NAT and encapsulation may obscure the packet's true source. Techniques have been developed to determine the source of large packet flows, but, to date, no system has been presented to track individual packets in an efficient, scalable fashion. We present a hash-based technique for IP traceback that generates audit trails for traffic within the network, and can trace the origin of a single IP packet delivered by the network in the recent past. We demonstrate that the system is effective, space efficient (requiring approximately 0.5% of the link capacity per unit time in storage), and implementable in current or next-generation routing hardware. We present both analytic and simulation results showing the system's effectiveness.Keywords
This publication has 18 references indexed in Scilit:
- On design and evaluation of "intention-driven" ICMP tracebackPublished by Institute of Electrical and Electronics Engineers (IEEE) ,2002
- Infrastructure for intrusion detection and responsePublished by Institute of Electrical and Electronics Engineers (IEEE) ,2002
- An analysis of using reflectors for distributed denial-of-service attacksACM SIGCOMM Computer Communication Review, 2001
- Network support for IP tracebackIEEE/ACM Transactions on Networking, 2001
- Characteristics of fragmented IP traffic on internet linksPublished by Association for Computing Machinery (ACM) ,2001
- Summary cache: a scalable wide-area Web cache sharing protocolIEEE/ACM Transactions on Networking, 2000
- End-to-end Internet packet dynamicsIEEE/ACM Transactions on Networking, 1999
- Requirements for IP Version 4 RoutersPublished by RFC Editor ,1995
- Universal classes of hash functionsJournal of Computer and System Sciences, 1979
- Space/time trade-offs in hash coding with allowable errorsCommunications of the ACM, 1970