Efficient Probabilistic Packet Marking for AS Traceback

Abdullah Yasin Nur · 2021

Distributed Denial of Service (DDoS) attacks are among the most perilous attack types in the Internet. In addition to the significant harms for the victim site, intermediate Autonomous Systems (AS) are also unintended victims in DDoS attacks. The main goal of a DDoS defense mechanism is to reduce the attack’s effect as close as possible to their sources to prevent malicious traffic in the Internet. In this work, we proposed an AS traceback scheme to infer AS level forward paths from attacker sites to a victim site. We utilize the 16-bit IP ID field and 6-bit from the ToS field in the IPv4 protocol. In our method, only the ingress routers of ASes probabilistically mark the packet with their AS numbers. We propose an encoding technique to reduce the number of required packets significantly. The destination site can construct the path after receiving enough packets. Our results show that a victim site can construct the forward path from an attacker site after receiving 10.14 packets on the average. Compared to the other techniques, our approach requires fewer packets to construct the paths from attacker sites to a victim site.

Read the paper · More papers on PaperTik