Performance evaluation of inter-domain IP traceback
Yuichiro Sawai, Masafumi Oe, Katsuyoshi Iida, Youki Kadobayashi · 2003
IP traceback is technology used to find the true source address of a Distributed Denial of Service (DDoS) attack with source address spoofing. We focus on IP option traceback (IP-OPT) for inter-domain IP traceback. In the Passive Detection Packet (PDP) method, which is a basic mechanism of IP-OPT, there is a trade off between the amount of trace traffic and the detection time for the path of attack time. However, no analysis of this condition has been made at this time. Thus, we mathematically analyze the tradeoff of PDP, and show that 1.1/spl times/10/sup -4/ is the optimal value of the pacekt generation probability for IP-OPT through numerical experiments.