作者: A. Yaar , A. Perrig , D. Song
DOI: 10.1109/INFCOM.2005.1498364
关键词: Computer network 、 IP traceback 、 Router 、 IP address spoofing 、 Quality of service 、 Denial-of-service attack 、 Domain Name System 、 Computer security 、 Computer science 、 The Internet 、 Network packet
摘要: Traceback mechanisms are a critical part of the defense against IP spoofing and DoS attacks, as well being forensic value to law enforcement. Currently proposed traceback inadequate address problem for following reasons: they require DDoS victims gather thousands packets reconstruct single attack path; do not scale large distributed attacks; support incremental deployment. We propose fast Internet (FIT), new packet marking approach that significantly improves in several dimensions: (1) can identify paths with high probability after receiving only tens packets, reduction 1-3 orders magnitude compared previous schemes; (2) FIT performs even presence legacy routers, allowing every FIT-enabled router path be identified; (3) scales attacks attackers. Compared schemes, represents step forward performance deployability.