An IP traceback mechanism for reflective DoS attacks
Bao-Tung Wang, Henning G. Schulzrinne · 2004
We present a new ICMP message and an automatic process capable of tracing reflective DoS attacks back to attack agents. The newly designed ICMP message carries the packet routing history and is signed by each forwarding router. After receiving the loaded ICMP messages, attack targets can identify the border routers of reflectors in the first flooding path and then use an ICMP message to inform accountable border routers to continue the traceback process to find the attack agents. In this paper, we propose an automatic, efficient, and secure traceback process across domains and discuss some limitations of the protocol.