A non-preemptive packet marking scheme
Yuan Liu, Xiaoqing Gu, Yaming Sun · 2006
Distributed denial of service (DDoS) attack is among the hardest network problems. Among several countermeasures, packet marking scheme is promising. In these schemes, every router marks a passing packet with a probability, so that the convergence time for an attacking path can be achieved in little time, and the attack can be found in attack path reconstruction using IP traceback. In this paper, a new non-preemptive packet marking scheme (NPM) is given, which reduces the convergence time and false positive rate, and takes lower network and router overhead