Branch Label Based Probabilistic Packet Marking for Counteracting DDoS Attacks(Security Issues)(<Special Section>Next Generation Networks Software)
スポンサーリンク
概要
- 論文の詳細を見る
Effective counteraction to Distributed Denial-of-Services (DDoS) attacks is a pressing problem over the Internet. For this counter-action, it is considered important to locate the router interfaces closest to the attackers in order to effectively filter a great number of identification jammed packets with spoofed source addresses from widely distributed area. Edge sample (ES) based Probabilistic Packet Marking (PPM) is an encouraging method to cope with source IP spoofing, which usually accompanies DDoS attacks. But its fragmentation of path information leads to inefficiency in terms of necessary number of packets, path calculation time and identification accuracy. We propose Branch Label (BL) based PPM to solve the above inefficiency problem. In BL, a whole single path information is marked in a packet without fragmentation in contrast to ES based PPM. The whole path information in packets by the BL approach is expressed with branch information of each router interfaces. This brings the following three key advantages in the process of detecting the interfaces: quick increase in true-positives detected (efficiency), quick decrease in false-negatives detected (accuracy) and fast convergence (quickness).
- 社団法人電子情報通信学会の論文
- 2004-07-01
著者
-
Nakamura Fumitaka
Hewlett-packard Japan Ltd.
-
Nakamura F
Nagoya Univ. Aichi
-
OGAWA Toshiaki
Hewlett-Packard Japan, Ltd.
-
WAKAHARA Yasushi
Hewlett-Packard Japan, Ltd.
-
Ogawa Toshiaki
Hewlett-packard Japan Ltd.
-
Wakahara Yasushi
Hewlett-packard Japan Ltd.
関連論文
- Fragmentation of Filamentary Molecular Clouds with Longitudinal and Helical Magnetic Fields
- Parker-Jeans Instability of the Galactic Gaseous Disk
- Parker-Jeans Instability of Gaseous Disks
- Branch Label Based Probabilistic Packet Marking for Counteracting DDoS Attacks(Security Issues)(Next Generation Networks Software)