Abstract

Aimed at loop fallacy, indeterminate serialisation of suspicious nodes and local overload problems of suspicious information source traceback in net-flow exchange, this paper proposes a multilayer collaborative traceback technique based on net-flow fingerprint. The traceback is divided into controllable inter-AS layer, intra-AS routing layer and controllable subnet layer. Based on the characteristics of each layer, it achieves efficient suspicious path extraction in controllable inter-AS layer by BGP protocol properties. In intra-AS routing layer, it solves loop fallacy by directed graph transformation and indeterminate serialisation of suspicious nodes by local time relationship approach. In controllable subnet layer, it achieves precise location by using forwarding tables. What is more, by proposing multilayer collaborative approach, it improves the efficiency of suspicious path extraction and reduces local overload of traceback servers without compromising the accuracy of traceback. Finally, the correctness and computational complexity of NFCMT are proved, and the feasibility and correctness of this scheme are discussed by experiments.

Talk to us

Join us for a 30 min session where you can share your feedback and ask us any queries you have

Schedule a call

Disclaimer: All third-party content on this website/platform is and will remain the property of their respective owners and is provided on "as is" basis without any warranties, express or implied. Use of third-party content does not indicate any affiliation, sponsorship with or endorsement by them. Any references to third-party content is to identify the corresponding services and shall be considered fair use under The CopyrightLaw.