MIB-ITrace-CP: An improvement of ICMP-based traceback efficiency in network forensic analysis

Bo Chao Cheng, Guo Tan Liao, Ching Kai Lin, Shih Chun Hsu, Ping Hai Hsu, Jong Hyuk Park

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

4 Scopus citations

Abstract

A denial-of-service (DoS) / distributed-denial-of-service (DDoS) attack may result in rapid resource depletion along the attack path. For steppingstone and masquerading techniques typically used in DoS/DDoS attacks such as internet protocol (IP) or Media Access Control (MAC) address spoofing, tracing the intrusion back to the true attacker becomes a challenging task for network security engineers. Although the Internet Engineer Task Force (IETF) has proposed an Internet Control Message Protocol (ICMP) based Traceback solution, it faces severe difficulties in practice in regard to justifying the interoperability of deployed routers as well as the correctness of Traceback with multiple attack paths. This research proposes a novel approach to embed the essence of a management information base (MIB) into iTrace messages, named MIB-ITrace-CP, in order to improve the accuracy and efficiency of the original ICMP-based Traceback. Through our implementations on a Testbed@TWISC platform, we validated our approach and demonstrated the feasibility of practical network forensics.

Original languageEnglish
Title of host publicationNetwork and Parallel Computing - 9th IFIP International Conference, NPC 2012, Proceedings
Pages101-109
Number of pages9
DOIs
StatePublished - 2012
Event9th IFIP International Conference on Network and Parallel Computing, NPC 2012 - Gwangju, Korea, Republic of
Duration: 6 Sep 20128 Sep 2012

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume7513 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference9th IFIP International Conference on Network and Parallel Computing, NPC 2012
Country/TerritoryKorea, Republic of
CityGwangju
Period6/09/128/09/12

Keywords

  • DoS
  • Forensics
  • ITrace-CP
  • Spoofing
  • Traceback

Fingerprint

Dive into the research topics of 'MIB-ITrace-CP: An improvement of ICMP-based traceback efficiency in network forensic analysis'. Together they form a unique fingerprint.

Cite this