Authenticated Deterministic Packet Marking Scheme(PDF)
南京师范大学学报(工程技术版)[ISSN:1006-6977/CN:61-1281/TN]
- Issue:
- 2007年02期
- Page:
- 67-71
- Research Field:
- Publishing date:
Info
- Title:
- Authenticated Deterministic Packet Marking Scheme
- Author(s):
- Zong Yian1; Dou Wanfeng1; 2
- 1.School of Mathematics and Computer Science,Nanjing Normal University,Nanjing 210097,China;2.National Important Laboratory of Computer Software New Technology,Nanjing University,Nanjing 210093,China
- Keywords:
- den ial of serv ice attack; IP traceback; dete rm inistic packetm a rking; MAC- based authentication
- PACS:
- TP393.01
- DOI:
- -
- Abstract:
- Determ in istic packet m ark ing ( DPM ) a lgo rithm only requires edge routers to pe rfo rm packe tm arking and can trace a large number of a ttackers sim ultaneously w ith on ly a few packets from each attacker. For that, comprom ised routers, e ither edge route rs o r transit routers, can eas ily forge packetm ark ings to prevent the v ictim perform ing reconstruction successfu lly. For that, a new schem e, nam ely MAC - based Authenticated DPM ( ADPM ), is proposed. Researches ind ica te that ADPM algor ithm supplies sufficien t secur ity tha t attackers in subnets o r com prom ised routers cannot forgem arkings, wh ich assures the veracity o f address reconstruc tion a t the v ictim.
Last Update: 2013-04-29