Single Packet AS Traceback against DoS Attacks

A. Nur, M. E. Tozal
{"title":"Single Packet AS Traceback against DoS Attacks","authors":"A. Nur, M. E. Tozal","doi":"10.1109/SysCon48628.2021.9447126","DOIUrl":null,"url":null,"abstract":"The Internet is every facet of our daily lives and becomes more pervasive every day. It is designed to forward packets with minimal intervention, including malicious packets. This design enables different attack types including Denial of Service (DoS), which is one of the most harmful cyber-attack types in the Internet. In this work, we propose an Autonomous System (AS) traceback packet marking scheme to infer AS level forward paths from attackers towards a victim site. We utilize the Record Route option of the IP protocol to implement our packet marking scheme. Traceback on the AS level has many advantages, including a significant reduction in the number of required packets to construct forward-paths from attackers toward a victim site, reduction in the number of routers that involves in the packet marking process, and lower packet size overhead to routers, comparing to interface level traceback. Our results show that a victim site can construct the AS level forward path from an attacker site after receiving a single packet. In our marking algorithm, we provide an encoding method to reduce the bandwidth usage. The proposed technique uses 96.91 bits on the average in the Record Route options field, whereas the unencoded version uses 153.96 bits on the average.","PeriodicalId":384949,"journal":{"name":"2021 IEEE International Systems Conference (SysCon)","volume":"4 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2021-04-15","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"4","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2021 IEEE International Systems Conference (SysCon)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/SysCon48628.2021.9447126","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 4

Abstract

The Internet is every facet of our daily lives and becomes more pervasive every day. It is designed to forward packets with minimal intervention, including malicious packets. This design enables different attack types including Denial of Service (DoS), which is one of the most harmful cyber-attack types in the Internet. In this work, we propose an Autonomous System (AS) traceback packet marking scheme to infer AS level forward paths from attackers towards a victim site. We utilize the Record Route option of the IP protocol to implement our packet marking scheme. Traceback on the AS level has many advantages, including a significant reduction in the number of required packets to construct forward-paths from attackers toward a victim site, reduction in the number of routers that involves in the packet marking process, and lower packet size overhead to routers, comparing to interface level traceback. Our results show that a victim site can construct the AS level forward path from an attacker site after receiving a single packet. In our marking algorithm, we provide an encoding method to reduce the bandwidth usage. The proposed technique uses 96.91 bits on the average in the Record Route options field, whereas the unencoded version uses 153.96 bits on the average.
针对DoS攻击的单包AS回溯
互联网是我们日常生活的方方面面,而且每天都变得越来越普遍。它被设计成以最小的干预转发数据包,包括恶意数据包。这种设计支持不同的攻击类型,包括拒绝服务(DoS),这是互联网上最有害的网络攻击类型之一。在这项工作中,我们提出了一个自治系统(AS)回溯数据包标记方案来推断从攻击者到受害者站点的AS级转发路径。我们利用IP协议的记录路由选项来实现我们的数据包标记方案。AS级别的回溯有很多优点,包括与接口级别的回溯相比,显著减少了构建从攻击者到受害站点的前向路径所需的数据包数量,减少了参与数据包标记过程的路由器数量,以及降低了路由器的数据包大小开销。我们的研究结果表明,受害站点可以在收到单个数据包后从攻击站点构建AS级转发路径。在我们的标记算法中,我们提供了一种编码方法来减少带宽的使用。提议的技术在记录路由选项字段中平均使用96.91位,而未编码的版本平均使用153.96位。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信