Computer Engineering and Applications ›› 2010, Vol. 46 ›› Issue (13): 4-7.DOI: 10.3778/j.issn.1002-8331.2010.13.002

New fragment marking algorithm for IP traceback

LV Jun-jie1,LIU Li2   

  1. 1.School of Business,Beijing Technology and Business University,Beijing 100048,China
    2.School of Information Engineering,University of Science and Technology Beijing,Beijing 100083,China
  • Received:2010-01-22 Revised:2010-03-09 Online:2010-05-01 Published:2010-05-01
吕俊杰1,刘 丽2   

  1. 1.北京工商大学 商学院,北京 100048
    2.北京科技大学 信息工程学院,北京 100083
Abstract: IP traceback is an important measure to defend against Denial of Service(DoS) attack.Based on Compressed Edge Fragment Sampling algorithm(CEFS) for IP traceback,a new fragment marking algorithm(NFMS) is proposed.By enlarging marking space and using adaptive probability for packet marking,the NFMS algorithm reduces the number of packets needed for path reconstruction.Moreover,the algorithm reduces computation and false positive number in reconstructing multiple path by labeling fragment.Then the algorithm strengthens the anti-interference capability by initializing marking space of packets which are not marked by Border Router.Finally the algorithm deposits node fragment and edge fragment separately,which can confirm the accuracy of the obtained node in attack path.Compared with other algorithms,the NFMS algorithm has better performance in the aspect of the number of packets needed for attack path reconstruction.

Key words: Denial of Service attack(DoS), IP traceback, packet marking, Compressed Edge Fragment Sampling algorithm(CEFS), adaptive probability fragment marking algorithm

摘要: 拒绝服务攻击(DoS)是难以解决的网络安全问题。IP追踪技术是确定DoS攻击源的有效方法。针对用于IP追踪的压缩边分片采样算法(CEFS)存在的不足,提出了新分片标记算法(NFMS),该算法通过扩大标记空间和采用自适应概率的方法,减少了重构路径所需数据包数,并通过给分片加标注,减少了重构路径的计算量和误报率,并且将点分片(路由器分片)、边分片(该路由器分片与同偏移值的下游相邻路由器分片的异或值)分开存放,可验证重构路径时所得攻击路径中节点的正确性。分析和仿真结果表明NFMS算法的性能较优。

关键词: 拒绝服务攻击(DoS), IP追踪, 包标记, 压缩边分片采样算法, 自适应概率分片标记算法

