Hash-based IP traceback

被引:149
作者
Snoeren, AC
Partridge, C
Sanchez, LA
Jones, CE
Tchakountio, F
Kent, ST
Strayer, WT
机构
[1] BBN Syst & Technol Corp, Cambridge, MA 02138 USA
[2] MIT, Comp Sci Lab, Cambridge, MA 02139 USA
关键词
D O I
10.1145/964723.383060
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The design of the IP protocol makes it difficult to reliably identify the originator of an IP packet. Even in the absence of any deliberate attempt to disguise a packet's origin, wide-spread packet forwarding techniques such as NAT and encapsulation may obscure the packet's true source. Techniques have been developed to determine the source of large packet flows, but, to date, no system has been presented to track individual packets in an efficient, scalable fashion. We present a hash-based technique for IP traceback that generates audit trails for traffic within the network, and can trace the origin of a single IP packet delivered by the network in the recent past. We demonstrate that the system is effective, space-efficient (requiring approximately 0.5% of the link capacity per unit time in storage), and implementable in current or next-generation routing hardware. We present both analytic and simulation results showing the system's effectiveness.
引用
收藏
页码:3 / 14
页数:12
相关论文
共 23 条
[1]  
[Anonymous], 2000, P 2000 ACM SIGCOMM C
[2]  
BAKER F, 1995, 1812 RFC IETF
[3]  
BELLOVIN SM, 2000, UNPUB ICMP TRACEBACK
[4]  
Black J., 1999, Advances in Cryptology - CRYPTO'99. 19th Annual International Cryptology Conference. Proceedings, P216, DOI 10.1007/3-540-48405-1_14
[5]   SPACE/TIME TRADE/OFFS IN HASH CODING WITH ALLOWABLE ERRORS [J].
BLOOM, BH .
COMMUNICATIONS OF THE ACM, 1970, 13 (07) :422-&
[6]  
BURCH H, 2000, P USENIX LISA 00 DEC
[7]  
CARTER JL, 1979, J COMPUT SYST SCI, V18, P143, DOI 10.1016/0022-0000(79)90044-8
[8]   Summary cache: A scalable wide-area Web cache sharing protocol [J].
Fan, L ;
Cao, P ;
Almeida, J ;
Broder, AZ .
IEEE-ACM TRANSACTIONS ON NETWORKING, 2000, 8 (03) :281-293
[9]  
Ferguson P, 1998, 2267 RFC IETF
[10]  
Halevi S, 1997, LECT NOTES COMPUT SC, V1267, P172