IP traceback system for denial-of-service attacks
Suratose Tritilanunt, Thananon Salakit, Patchpon Achwacheewanthornkul · 2014
Tracing denial-of-service (DoS) attacks back to their source is a difficult task for network administrators. The source of attacks, sometimes, comes from a single source or multiple sources that makes harder to an investigator to trace attackers back to their original computer. In order to make attacks more difficult to discover, sophisticated attackers could hide their original IP address by using spoofing techniques, or they can cover themselves by launching attacks behind the proxy. This paper provides a detection and IP traceback mechanism that be able to identify a source of DoS attacks in three different scenarios. By setting up the experiment, the experimental results demonstrate that our approach is able to detect a computer that generates denial-of-service attacks, even these attacks are located behind a proxy.