A robust packet-filtering method for high-bandwidth aggregates
Bao-Tung Wang, Henning G. Schulzrinne · 2004
We propose a robust approach that integrates the concepts of IP traceback and packet filtering. On one hand, our approach employs an IP traceback technique to identify the paths and the sources of the attack at the victim's system; on the other, in accordance with the result from the IP traceback, the victim is eligible to request routers close to the attack origins for packet filtering. The reason that our approach is robust is that during the IP traceback process, the victim receives essential information indicating the origins of flooding packets. Most importantly, the information will have been signed by the packet-filtering router itself. The request authentication is indispensable because otherwise an attacker can simply manipulate the packet filtering mechanism to intentionally drop specific IP packets and launch a successful DoS attack.