作者: Ruiliang Chen , Jung-Min Park , Randolph Marchany
关键词:
摘要: Distributed Denial-of-Service (DDoS) attacks have become a major threat to the Internet. As countermeasure against DDoS attacks, IP traceback schemes identify network paths attack traffic traverses. This paper presents novel scheme called Router Interface Marking (RIM). In RIM, router probabilistically marks packets with interface's identifier. After collecting marked by each in an path, victim machine can use information trace back source. Different from most existing schemes, RIM of interfaces rather than that addresses. difference endows several advantageous features, including fast speed, last-hop capability, small computation overhead, low occurrence false positives, and enhanced security.