NCSU Libraries
Search the Collection|Browse Subjects|Services|Library Information|Community |News & Events

Title page for ETD etd-01062004-093357


Type of Document Dissertation
Author WU, CHIEN-LUNG ,
Author's Email Address cwu@deltartp.com
URN etd-01062004-093357
Title On Network-Layer Packet Traceback: Tracing Denial-of-Service (DoS) and Distributed Denial-of-Service (DDoS) Attacks
Degree PhD
Graduate Program Electrical Engineering
Advisory Committee
Advisor Name Title
Arne A. Nilsson Committee Chair
Shyhtsun Felix Wu Committee Co-Chair
Edward Gehringer Committee Member
George N. Rouskas Committee Member
Keywords
  • Hybrid iTrace
  • Intention-Driven iTrace
  • Traceback
  • DoS
  • DDoS
  • iTrace
  • ICMP Traceback
  • IPSec
  • Network-Layer Tracing
Date of Defense 2002-09-27
Availability unrestricted
Abstract
ABSTRACT:

The objective of this research is to study the Internet Protocol (IP) traceback technique in defeating Denial-of-Service (DoS) and Distributed Denial-of-Service (DDoS) attacks. Tracing attackers is the first and most important step to solve the DoS/DDoS problem. In this dissertation, two new traceback techniques, PHIL and Intention-Driven iTrace, are proposed and evaluated. Based on the IPSec infrastructure, previously, the Decentralized Source Identification for Network-based Intrusions (DECIDUOUS) module has been implemented and evaluated. However, in order to trace attack sources across different administrative domains securely, the notion of Packet Header Information List (PHIL) for IPSec is proposed to enhance DECIDUOUS module. Second, it is shown, in this thesis, that the iTrace (ICMP traceback, being standardized in IETF) has some serious drawbacks. To overcome these drawbacks, the Intention-Driven iTrace (ID-iTrace) and the Hybrid iTrace schemes are proposed. Our simulation results confirm that the original iTrace scheme is not able to handle low attack traffic well. From our simulation, the Hybrid iTrace scheme is evaluated and demonstrated to be an efficient and practical mechanism for tracing DoS/DDoS attacks.

Files
  Filename       Size       Approximate Download Time (Hours:Minutes:Seconds) 
 
 28.8 Modem   56K Modem   ISDN (64 Kb)   ISDN (128 Kb)   Higher-speed Access 
  etd.pdf 3.06 Mb 00:14:08 00:07:16 00:06:21 00:03:10 00:00:16