Two-Tier Packet Labeling for DDoS Traceback
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current data network traceback techniques are inadequate in accurately identifying the source of DDoS attacks due to spoofed IP addresses, requiring significant packet analysis and being vulnerable to tampering, and are not incrementally deployable or scalable.
Innovation Solution
A two-tier labeling technique is implemented, using distance-2 graph labeling for autonomous systems and unique tier 2 labels for border routers, with logical partitioning to reduce label requirements and enable probabilistic labeling of data packets, allowing for efficient traceback with minimal packet analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If packet marking techniques are used to mark data packets with partial path information, then the attack path can be reconstructed, but the technique requires analysis of a large number of packets and is vulnerable to tampering
Solution Approach 1:
The patent segments the network into autonomous systems (ASes) and applies labeling at the AS level rather than at individual router level. This segmentation reduces the total number of labels needed and allows traceback to be performed by analyzing fewer packets, as each AS contributes at least one labeled packet to the traceback process.
Solution Approach 2:
The patent applies preliminary labeling to autonomous systems before the attack occurs. Each AS is pre-assigned a label, and border routers are pre-configured with their AS label. When an attack occurs, these pre-labeled packets can be immediately analyzed for traceback, eliminating the need for real-time labeling during the attack and reducing the number of packets that need to be analyzed.
2Loss of information
If traditional packet marking is implemented across all routers, then complete path information is obtained, but the deployment is complex and not incrementally deployable
Solution Approach 1:
The patent divides the network into autonomous systems and performs labeling at the AS level rather than requiring every router to participate. Only border routers (those connecting to other ASes) need to be configured with the traceback functionality, significantly reducing deployment complexity while still providing complete path information through the sequence of AS labels.
Solution Approach 2:
The patent makes the traceback mechanism universal by having each autonomous system contribute to the traceback process. Any AS along the attack path can provide its label, and the system works regardless of which specific routers are involved. This multi-functional approach allows incremental deployment where any AS can join the traceback system independently.
3Measurement precision
If unique labels are assigned to each router, then precise location is identified, but the number of labels required becomes unmanageably large
Solution Approach 1:
The patent merges multiple routers within an autonomous system under a single AS label. Instead of assigning unique labels to individual routers, all routers in an AS share the same label. This dramatically reduces the total number of labels required while still providing precise source identification through the sequence of AS labels and the identification of the specific border router.
Solution Approach 2:
The patent shifts from a one-dimensional router-level labeling scheme to a two-dimensional AS-level labeling scheme. By organizing labels at the AS level rather than router level, the system reduces the total number of labels needed while maintaining traceback capability through the hierarchical structure of AS sequences and border router identification.
4Measurement precision
If packet logging stores packet digests in all routers, then the attack path can be reconstructed, but the technique is vulnerable to spoofed information and compromised routers
Solution Approach 1:
The patent introduces autonomous systems as intermediaries between individual routers and the traceback analysis. Instead of relying on individual router labels that could be spoofed, the AS label acts as a trusted intermediary that aggregates multiple routers. This hierarchical structure makes it more difficult for attackers to spoof information, as they would need to compromise entire ASes rather than individual routers.
Data Source
AI summary
Disclosed is a two tier packet labeling technique for use in connection with network traceback in a network having multiple autonomous systems, with routers and other network resources within each autonomous system. Tier 1 labels are assigned at the autonomous system level, and tier 2 labels are assigned at the router level. In order to reduce the number of labels that are required, a technique called logical partitioned coloring may be used, in which certain autonomous systems and border routers may be logically partitioned into a plurality of mesh connected nodes, and the labels are assigned to these mesh-connected nodes. During network operation the network routers store either tier 1 or tier 2 labels in data packets. The determination of whether to store a label in any particular packet, and the determination of which label to store, may be determined probabilistically by the network router.


