Cargando…

Hybrid Single-Packet IP Traceback with Low Storage and High Accuracy

Traceback schemes have been proposed to trace the sources of attacks that usually hide by spoofing their IP addresses. Among these methods, schemes using packet logging can achieve single-packet traceback. But packet logging demands high storage on routers and therefore makes IP traceback impractica...

Descripción completa

Detalles Bibliográficos
Autor principal: Yang, Ming Hour
Formato: Online Artículo Texto
Lenguaje:English
Publicado: Hindawi Publishing Corporation 2014
Materias:
Acceso en línea:https://www.ncbi.nlm.nih.gov/pmc/articles/PMC3953451/
https://www.ncbi.nlm.nih.gov/pubmed/24707197
http://dx.doi.org/10.1155/2014/239280
_version_ 1782307358705188864
author Yang, Ming Hour
author_facet Yang, Ming Hour
author_sort Yang, Ming Hour
collection PubMed
description Traceback schemes have been proposed to trace the sources of attacks that usually hide by spoofing their IP addresses. Among these methods, schemes using packet logging can achieve single-packet traceback. But packet logging demands high storage on routers and therefore makes IP traceback impractical. For lower storage requirement, packet logging and packet marking are fused to make hybrid single-packet IP traceback. Despite such attempts, their storage still increases with packet numbers. That is why RIHT bounds its storage with path numbers to guarantee low storage. RIHT uses IP header's ID and offset fields to mark packets, so it inevitably suffers from fragment and drop issues for its packet reassembly. Although the 16-bit hybrid IP traceback schemes, for example, MORE, can mitigate the fragment problem, their storage requirement grows up with packet numbers. To solve the storage and fragment problems in one shot, we propose a single-packet IP traceback scheme that only uses packets' ID field for marking. Our major contributions are as follows: (1) our fragmented packets with tracing marks can be reassembled; (2) our storage is not affected by packet numbers; (3) it is the first hybrid single-packet IP traceback scheme to achieve zero false positive and zero false negative rates.
format Online
Article
Text
id pubmed-3953451
institution National Center for Biotechnology Information
language English
publishDate 2014
publisher Hindawi Publishing Corporation
record_format MEDLINE/PubMed
spelling pubmed-39534512014-04-06 Hybrid Single-Packet IP Traceback with Low Storage and High Accuracy Yang, Ming Hour ScientificWorldJournal Research Article Traceback schemes have been proposed to trace the sources of attacks that usually hide by spoofing their IP addresses. Among these methods, schemes using packet logging can achieve single-packet traceback. But packet logging demands high storage on routers and therefore makes IP traceback impractical. For lower storage requirement, packet logging and packet marking are fused to make hybrid single-packet IP traceback. Despite such attempts, their storage still increases with packet numbers. That is why RIHT bounds its storage with path numbers to guarantee low storage. RIHT uses IP header's ID and offset fields to mark packets, so it inevitably suffers from fragment and drop issues for its packet reassembly. Although the 16-bit hybrid IP traceback schemes, for example, MORE, can mitigate the fragment problem, their storage requirement grows up with packet numbers. To solve the storage and fragment problems in one shot, we propose a single-packet IP traceback scheme that only uses packets' ID field for marking. Our major contributions are as follows: (1) our fragmented packets with tracing marks can be reassembled; (2) our storage is not affected by packet numbers; (3) it is the first hybrid single-packet IP traceback scheme to achieve zero false positive and zero false negative rates. Hindawi Publishing Corporation 2014-02-23 /pmc/articles/PMC3953451/ /pubmed/24707197 http://dx.doi.org/10.1155/2014/239280 Text en Copyright © 2014 Ming Hour Yang. https://creativecommons.org/licenses/by/3.0/ This is an open access article distributed under the Creative Commons Attribution License, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.
spellingShingle Research Article
Yang, Ming Hour
Hybrid Single-Packet IP Traceback with Low Storage and High Accuracy
title Hybrid Single-Packet IP Traceback with Low Storage and High Accuracy
title_full Hybrid Single-Packet IP Traceback with Low Storage and High Accuracy
title_fullStr Hybrid Single-Packet IP Traceback with Low Storage and High Accuracy
title_full_unstemmed Hybrid Single-Packet IP Traceback with Low Storage and High Accuracy
title_short Hybrid Single-Packet IP Traceback with Low Storage and High Accuracy
title_sort hybrid single-packet ip traceback with low storage and high accuracy
topic Research Article
url https://www.ncbi.nlm.nih.gov/pmc/articles/PMC3953451/
https://www.ncbi.nlm.nih.gov/pubmed/24707197
http://dx.doi.org/10.1155/2014/239280
work_keys_str_mv AT yangminghour hybridsinglepacketiptracebackwithlowstorageandhighaccuracy