A Novel Deterministic Packet Marking Scheme for IP Traceback
Zhaoyang Qu, Chunfeng Huang · 2008
This paper proposes a novel deterministic packet marking (NDPM) scheme for IP traceback. It mainly marks packets with IP addresses and the number of current autonomous system (AS) through border gateway protocol (BGP) routers. According to the marked information in the packets, victims can not only trace the attack source to the original AS, but also can filter the malicious packets, hence making it possible to alleviate the impact caused by attack traffic on the victims. It resolves the disadvantages of the traditional packet marking methods with heavy computational overhead and low speed of tracing back to the attack source. At the same time, it doesn't need all the routers' participation in marking in the attack path, which greatly reduces the overhead of routers.