Proposal and Its Implementation of L2-based IP Trace Back Method
宏和 播磨, Masashi Ito, Hidekazu Suzuki, Naonobu Okazaki, Akira Watanabe · 2008
With the increase of population who use the Internet, DoS attacks by malicious users are becoming serious problems. It is difficalt to prevent DoS attacks by setting up Firewalls or using router’s filtering functions, because it is difficult to distinguish DoS attacks from normal accesses. It is said that identifying the attacker is quite difficult, because source IP addresses of packets are always forged. Though there have been several studies on IP trace back technologies, there still remain problems that tracing mechanism is not so accurate, and the loads of routers are so high. In this paper, we propose L2-based IP trace back method noting that layer2 addresses of routers are impossible to forge. The proposed method generates the information that identifies the attacking route only when the number of forwarded packets exceeds the predetermined threshold value. Threshold values are determined according to each Dos attack using signature, in order to detect several types of DoS attacks. We have implemented and evaluationed the proposed method, and it has been confirmed that the loads of routers are sufficiently small and it can detect several types of DoS attacks effectively.