as级部分部署场景下的单包IP回溯

T. Korkmaz, Chao Gong, K. Saraç, S. G. Dykes
{"title":"as级部分部署场景下的单包IP回溯","authors":"T. Korkmaz, Chao Gong, K. Saraç, S. G. Dykes","doi":"10.1504/IJSN.2007.012828","DOIUrl":null,"url":null,"abstract":"Tracing IP packets to their sources, known as IP traceback, is an important task in defending against IP spoofing and DoS attacks. Log-based IP traceback technique is to log packets at routers in the network and then determine the network paths which packets traversed using data extraction techniques. The biggest advantage of log-based IP traceback is the potential to trace a single packet. Tracing a single packet in the Internet using log-based IP traceback involves cooperation among all autonomous systems (AS) traversed by the packet. The single packet traceback process may not reach the packet origin if some AS on the forwarding path does not support IP traceback. IP traceback mechanisms are deployed within each AS independently. It is not reasonable to assume all ASes begin to support the same IP traceback mechanism in a short period of time. In this paper, we study the effectiveness of log-based IP traceback in tracing a single packet under the environment where not every AS supports log-based IP traceback. We propose a scheme to conduct the single packet traceback process in AS-level partial deployment scenario. We evaluate the performance of single packet IP traceback in AS-level partial deployment scenario based on our scheme through simulation.","PeriodicalId":319736,"journal":{"name":"GLOBECOM '05. IEEE Global Telecommunications Conference, 2005.","volume":"21 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2005-12-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"76","resultStr":"{\"title\":\"Single packet IP traceback in AS-level partial deployment scenario\",\"authors\":\"T. Korkmaz, Chao Gong, K. Saraç, S. G. Dykes\",\"doi\":\"10.1504/IJSN.2007.012828\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Tracing IP packets to their sources, known as IP traceback, is an important task in defending against IP spoofing and DoS attacks. Log-based IP traceback technique is to log packets at routers in the network and then determine the network paths which packets traversed using data extraction techniques. The biggest advantage of log-based IP traceback is the potential to trace a single packet. Tracing a single packet in the Internet using log-based IP traceback involves cooperation among all autonomous systems (AS) traversed by the packet. The single packet traceback process may not reach the packet origin if some AS on the forwarding path does not support IP traceback. IP traceback mechanisms are deployed within each AS independently. It is not reasonable to assume all ASes begin to support the same IP traceback mechanism in a short period of time. In this paper, we study the effectiveness of log-based IP traceback in tracing a single packet under the environment where not every AS supports log-based IP traceback. We propose a scheme to conduct the single packet traceback process in AS-level partial deployment scenario. We evaluate the performance of single packet IP traceback in AS-level partial deployment scenario based on our scheme through simulation.\",\"PeriodicalId\":319736,\"journal\":{\"name\":\"GLOBECOM '05. IEEE Global Telecommunications Conference, 2005.\",\"volume\":\"21 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2005-12-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"76\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"GLOBECOM '05. IEEE Global Telecommunications Conference, 2005.\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1504/IJSN.2007.012828\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"GLOBECOM '05. IEEE Global Telecommunications Conference, 2005.","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1504/IJSN.2007.012828","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 76

摘要

跟踪IP数据包的来源,即IP溯源,是防御IP欺骗和DoS攻击的重要任务。基于日志的IP回溯技术是对网络中路由器上的数据包进行日志记录,然后利用数据提取技术确定数据包所经过的网络路径。基于日志的IP回溯的最大优点是可以跟踪单个数据包。使用基于日志的IP回溯在Internet中跟踪单个数据包涉及到数据包所经过的所有自治系统(AS)之间的合作。如果转发路径上的某个自治系统不支持IP溯源,可能导致单报文溯源过程无法到达报文源。IP回溯机制在每个应用服务器内独立部署。假设所有的ase在短时间内开始支持相同的IP追溯机制是不合理的。在本文中,我们研究了在不是每个AS都支持基于日志的IP追溯的环境下,基于日志的IP追溯在跟踪单个数据包时的有效性。提出了一种在as级部分部署场景下进行单包回溯处理的方案。通过仿真,评估了该方案在as级部分部署场景下的单包IP溯源性能。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
Single packet IP traceback in AS-level partial deployment scenario
Tracing IP packets to their sources, known as IP traceback, is an important task in defending against IP spoofing and DoS attacks. Log-based IP traceback technique is to log packets at routers in the network and then determine the network paths which packets traversed using data extraction techniques. The biggest advantage of log-based IP traceback is the potential to trace a single packet. Tracing a single packet in the Internet using log-based IP traceback involves cooperation among all autonomous systems (AS) traversed by the packet. The single packet traceback process may not reach the packet origin if some AS on the forwarding path does not support IP traceback. IP traceback mechanisms are deployed within each AS independently. It is not reasonable to assume all ASes begin to support the same IP traceback mechanism in a short period of time. In this paper, we study the effectiveness of log-based IP traceback in tracing a single packet under the environment where not every AS supports log-based IP traceback. We propose a scheme to conduct the single packet traceback process in AS-level partial deployment scenario. We evaluate the performance of single packet IP traceback in AS-level partial deployment scenario based on our scheme through simulation.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Route discovery and capacity of ad hoc networks An algorithm for exploiting channel time selectivity in pilot-aided MIMO systems Consistent proportional delay differentiation: a fuzzy control approach Quantization bounds on Grassmann manifolds of arbitrary dimensions and MIMO communications with feedback Hash-AV: fast virus signature scanning by cache-resident filters
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1