Attak Flow Traceback

Heejin Jang, Hosang Yun, Seongkee Lee · 2008

Identifying the sources of attack packets is the first step in making attackers accountable under the current stateless network routing infrastructure. Several IP packet traceback mechanisms have been designed to attribute the origin of attack conducted not only by flooding network but by single well-targeted packet. However, it is still major challenge to reduce memory space and enhance traceback accuracy in today's high speed networks. In this paper, we propose an attack flow traceback scheme which is based on flow digests and network layer data. Digesting flow instead of individual packet would save memory and be more scalable. Storing network layer data makes it possible to identify attacker node itself on the subnet not the ingress point of an attacking packet and reduce a lot of unnecessary queries which used to be originated in traceback process.

Read the paper · More papers on PaperTik