A Low Traceback and Zero Logging Overhead IP Traceback Approach for Communication Networks
Subramaniam Malliga, Shanmuga Vadivel Kogilavani, P. S. Nandhini · 2018
In an IP address spoofing attack, attackers send IP packets from a forged source address in order to camouflage themselves. Denial of Service attacks quite often employ IP spoofing to overwhelm a target with packets that appear to have come from legitimate IP addresses. Such attacks may be prevented by tracing these attacks back to their origin. IP traceback is a technique which plays a vital role in finding the source of spoofed packets. This paper reviews an ICMP traceback method, SPITRI and suggests a few changes in the way the packets are marked and tracked back. The proposed marking scheme reduces the number of clock cycles needed for marking and tracking back. Also, it does not require logging at any of the routers. The simulation results demonstrate that the refinements reduce the time for marking and tracing back with 100% accuracy.