Attack source identification at router level in real time using marking algorithm deployed in programmable routers
T. Subbulakshmi, I. A. Aananda Guru, S. Mercy Shalinie · 2011
One of the Major threats to the current networks is Distributed Denial of Service (DDoS) Attack. Mechanisms are developed to detect the origin of DDoS attacks. The main issue concerned with detection systems is IP spoofing. This paper proposes a packet marking scheme which marks router information into IP header field of the packet to overcome the issue of IP spoofing. The marked information is used to reconstruct the IP address of the ingress router connected to the attack source at the detecting end. The work is deployed in the programmable routers in real time and the attack source detection mechanisms are carried out. Attack sources are detected from the marked information in the IP header of the packet. As the detection scheme relies only on the marked information in the IP header fields, the source of the spoofed packets can also be accurately identified.