Trace IP packets by flexible deterministic packet marking (FDPM)

Yang Xiang, Wanlei Zhou · 2005

Currently a large number of the notorious distributed denial of service (DDoS) attack incidents make people aware of the importance of the IP traceback technique. IP traceback is the ability to trace the IP packets to their origins. It provides a security system with the capability of identifying the true sources of the attacking IP packets. IP traceback mechanisms have been researched for years, aiming at finding the sources of IP packets quickly and precisely. In this paper, an IP traceback scheme, flexible deterministic packet marking (FDPM), is proposed. It provides more flexible features to trace the IP packets and can obtain better tracing capability over other IP traceback mechanisms, such as link testing, messaging, logging, probabilistic packet marking (PPM), and deterministic packet marking (DPM). The implementation and evaluation demonstrates that the FDPM needs moderately a small number of packets to complete the traceback process and requires little computation work; therefore this scheme is powerful to trace the IP packets. It can be applied in many security systems, such as DDoS defense systems, intrusion detection systems (IDS), forensic systems, and so on.

Read the paper · More papers on PaperTik