A Practical Hybrid IP Traceback Method under IPv6
Yulong Wang, Sui Tong -, Yi Yang · Journal of Convergence Information Technology · 2012
Recently, Distributed Denial of Service (DDoS) attacks have been threatening the Internet severely. Tracing IP packets back to their origins is an efficient and important part of the defense against those attacks. Currently two major kinds of IP traceback methods have been used for IP traceback in IPv6: packet marking and packet logging. IP traceback based on packet marking requires routers to write their identifiable information into the forwarded packets. It incurs little overhead on routers but needs a large number of packets to construct the complete attack path. IP traceback based on packet logging requires routers to store the digests of the forwarded packets. It only needs a few packets to construct the attack path but causes high storage overhead in routers. In this paper, we present a practical hybrid IP traceback method under IPv6 (PHIT-IPv6) which integrates packet marking and packet logging so as to obtain both of their advantages. We improved the practicality of DDoS traceback in that our method requires a less number of packets to conduct the traceback progress and reduces the storage overload of the intermediate routers for packet logging. We present both mathematical analysis and simulation of our method. The results show that our method can reduce the storage overhead by almost fifty percent and can also significantly decrease the number of packets for attack path construction.