Enhanced probabilistic packet marking traceback mechanism
Wei Peng Tan · 2006
Distributed Denial of Service (DDoS) attacks on the Internet have become a pressing issue following several high-profile attacks on e-commerce enterprises like Yahoo, Amazon and Ebay [2] [3].New occurrences of DDoS attack continue to be reported and threats have continued to increase.A recent DDoS attack was aimed at 13 root servers that offer the primary roadmap for approximately all Internet infrastructures [60].It was the largest and most complex DDoS attack ever and only four or five of the root server systems were able to endure the attack and stay available to legitimate users throughout the attack.It is difficult to defend against DDoS because of the lack of security features in TCP/IP specifications.Due to the stateless nature of the Internet, it is difficult to determine the true sources of spoofed IP packets.This thesis will first explore the various issues involved in an IP Traceback scheme, Probabilistic Packet Marking (PPM).In PPM, routers will probabilistically mark packets with partial path information.Based on this information in the marked packets, the victim tries to reconstruct the full path even though the IP addresses of the packets are spoofed.However, PPM suffers from high combination overhead and large number of false positives during path reconstruction.Attackers can also introduce uncertainty by inserting fake path information in the attack packets.Another disadvantage is that it is incapable of performing effective traceback for a large scale DDoS attack.This thesis introduces two new schemes: Entropy-Minimization Clustering Technique for Probabilistic Packet Marking Scheme [102] and Legitimacy Investigation and Intention-Based Probabilistic Packet Marking Scheme [103] to improve the performance of PPM.The first scheme, Entropy-Minimization Clustering Technique for Probabilistic Packet Marking Scheme is developed to provide a more effective traceback mechanism.The new technique divides the attack traffic into clusters and processes them in parallel.