Practical network support for IP traceback

Citation
S. Savage et al., Practical network support for IP traceback, COMP COM R, 30(4), 2000, pp. 295-306
Citations number
43
Categorie Soggetti
Information Tecnology & Communication Systems
Journal title
SIGCOMM computer communication review
ISSN journal
01464833 → ACNP
Volume
30
Issue
4
Year of publication
2000
Pages
295 - 306
Database
ISI
SICI code
0146-4833(200010)30:4<295:PNSFIT>2.0.ZU;2-J
Abstract
This paper describes a technique for tracing anonymous packet flooding atta cks in the Internet back towards their source. This work is motivated by th e increased frequency and sophistication of denial-of-service attacks and b y the difficulty in tracing packets with incorrect, or "spoofed", source ad dresses. In this paper we describe a general purpose traceback mechanism ba sed on probabilistic packet marking in the network. Our approach allows a v ictim to identify the network path(s) traversed by attack traffic without r equiring interactive operational support from Internet Service Providers (I SPs). Moreover, this traceback can be performed "post-mortem" - after an at tack has completed. We present an implementation of this technology that is incrementally deployable, (mostly) backwards compatible and can be efficie ntly implemented using conventional technology.