Cargando…
Hybrid Single-Packet IP Traceback with Low Storage and High Accuracy
Traceback schemes have been proposed to trace the sources of attacks that usually hide by spoofing their IP addresses. Among these methods, schemes using packet logging can achieve single-packet traceback. But packet logging demands high storage on routers and therefore makes IP traceback impractica...
Autor principal: | |
---|---|
Formato: | Online Artículo Texto |
Lenguaje: | English |
Publicado: |
Hindawi Publishing Corporation
2014
|
Materias: | |
Acceso en línea: | https://www.ncbi.nlm.nih.gov/pmc/articles/PMC3953451/ https://www.ncbi.nlm.nih.gov/pubmed/24707197 http://dx.doi.org/10.1155/2014/239280 |
_version_ | 1782307358705188864 |
---|---|
author | Yang, Ming Hour |
author_facet | Yang, Ming Hour |
author_sort | Yang, Ming Hour |
collection | PubMed |
description | Traceback schemes have been proposed to trace the sources of attacks that usually hide by spoofing their IP addresses. Among these methods, schemes using packet logging can achieve single-packet traceback. But packet logging demands high storage on routers and therefore makes IP traceback impractical. For lower storage requirement, packet logging and packet marking are fused to make hybrid single-packet IP traceback. Despite such attempts, their storage still increases with packet numbers. That is why RIHT bounds its storage with path numbers to guarantee low storage. RIHT uses IP header's ID and offset fields to mark packets, so it inevitably suffers from fragment and drop issues for its packet reassembly. Although the 16-bit hybrid IP traceback schemes, for example, MORE, can mitigate the fragment problem, their storage requirement grows up with packet numbers. To solve the storage and fragment problems in one shot, we propose a single-packet IP traceback scheme that only uses packets' ID field for marking. Our major contributions are as follows: (1) our fragmented packets with tracing marks can be reassembled; (2) our storage is not affected by packet numbers; (3) it is the first hybrid single-packet IP traceback scheme to achieve zero false positive and zero false negative rates. |
format | Online Article Text |
id | pubmed-3953451 |
institution | National Center for Biotechnology Information |
language | English |
publishDate | 2014 |
publisher | Hindawi Publishing Corporation |
record_format | MEDLINE/PubMed |
spelling | pubmed-39534512014-04-06 Hybrid Single-Packet IP Traceback with Low Storage and High Accuracy Yang, Ming Hour ScientificWorldJournal Research Article Traceback schemes have been proposed to trace the sources of attacks that usually hide by spoofing their IP addresses. Among these methods, schemes using packet logging can achieve single-packet traceback. But packet logging demands high storage on routers and therefore makes IP traceback impractical. For lower storage requirement, packet logging and packet marking are fused to make hybrid single-packet IP traceback. Despite such attempts, their storage still increases with packet numbers. That is why RIHT bounds its storage with path numbers to guarantee low storage. RIHT uses IP header's ID and offset fields to mark packets, so it inevitably suffers from fragment and drop issues for its packet reassembly. Although the 16-bit hybrid IP traceback schemes, for example, MORE, can mitigate the fragment problem, their storage requirement grows up with packet numbers. To solve the storage and fragment problems in one shot, we propose a single-packet IP traceback scheme that only uses packets' ID field for marking. Our major contributions are as follows: (1) our fragmented packets with tracing marks can be reassembled; (2) our storage is not affected by packet numbers; (3) it is the first hybrid single-packet IP traceback scheme to achieve zero false positive and zero false negative rates. Hindawi Publishing Corporation 2014-02-23 /pmc/articles/PMC3953451/ /pubmed/24707197 http://dx.doi.org/10.1155/2014/239280 Text en Copyright © 2014 Ming Hour Yang. https://creativecommons.org/licenses/by/3.0/ This is an open access article distributed under the Creative Commons Attribution License, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited. |
spellingShingle | Research Article Yang, Ming Hour Hybrid Single-Packet IP Traceback with Low Storage and High Accuracy |
title | Hybrid Single-Packet IP Traceback with Low Storage and High Accuracy |
title_full | Hybrid Single-Packet IP Traceback with Low Storage and High Accuracy |
title_fullStr | Hybrid Single-Packet IP Traceback with Low Storage and High Accuracy |
title_full_unstemmed | Hybrid Single-Packet IP Traceback with Low Storage and High Accuracy |
title_short | Hybrid Single-Packet IP Traceback with Low Storage and High Accuracy |
title_sort | hybrid single-packet ip traceback with low storage and high accuracy |
topic | Research Article |
url | https://www.ncbi.nlm.nih.gov/pmc/articles/PMC3953451/ https://www.ncbi.nlm.nih.gov/pubmed/24707197 http://dx.doi.org/10.1155/2014/239280 |
work_keys_str_mv | AT yangminghour hybridsinglepacketiptracebackwithlowstorageandhighaccuracy |