A novel deterministic packet marking scheme for IP trace back against distributed denial of service attacks is presented. Besides the hash correlation functions, our scheme has a unique technique: redundant decomposition, which plays an important role in improving the recovery performance. Theoretical analyses, the pseudo code and the experimental results are provided. The scheme is proved to be accurate and efficient and can handle large-scale DDoS attacks.
Published in:
Communications Letters, IEEE
(Volume:10
,
Issue:
3
)
Date of Publication: Mar 2006