IP Tracing and Active Network Response
Tarek S. Sobh, Awad H. Khalil

TL;DR
This paper introduces an integrated active security response model with mechanisms for tracing anonymous attacks and reconfiguring networks to counteract DoS and DDoS attacks.
Contribution
It presents a novel active response mechanism combining Sleepy Watermark Tracing and Probabilistic Packet Marking for effective attack source identification.
Findings
Effective attack source tracing demonstrated.
Network vulnerabilities can be detected and reconfigured.
Rapid active response against attackers achieved.
Abstract
Active security is mainly concerned with performing one or more security functions when a host in a communication network is subject to an attack. Such security functions include appropriate actions against attackers. To properly afford active security actions a set of software subsystems should be integrated together so that they can automatically detect and appropriately address any vulnerability in the underlying network. This work presents integrated model for active security response model. The proposed model introduces Active Response Mechanism (ARM) for tracing anonymous attacks in the network back to their source. This work is motivated by the increased frequency and sophistication of denial-of-service attacks and by the difficulty in tracing packets with incorrect, or "spoofed", source addresses. This paper presents within the proposed model two tracing approaches based on:…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsNetwork Security and Intrusion Detection · Internet Traffic Analysis and Secure E-voting · Advanced Malware Detection Techniques
