hash based IP traceback problems- draft-ietf-itrace-02.txt
"Rajesh Kumar Dilli" <[email protected]> Mon, 13 Jan 2003 16:21:17 -0800
| Newsgroups | gmane.ietf.itrace |
|---|---|
| Message-ID | <000001c2bb62$f643c1e0$0700a8c0@compsec> |
Hi,
I 'm working on IP traceback as part of my research work. I had
gone through this discussion list from starting (Feb 2000) to find out
the various approaches that have been used. In one of the drafts by
Bellovin draft-ietf-itrace-02.txt
<http://www.ietf.org/internet-drafts/draft-ietf-itrace-02.txt> there
was a note about the Hash based IP traceback approach. The point that is
mentioned in this draft (given below) seems to be little confusing.
"The problem is that queries must be done very soon after
the attack, unless the routers
have some way of offloading historical data to bulk storage."
In the original paper by Snoeren
http://nms.lcs.mit.edu/~snoeren/papers/spie-ton.pdf the author states
that
"The amount of time during which queries can be supported is
directly dependent on the amount of memory dedicated to
SPIE. The appropriate amount of time varies depending upon the
responsiveness of the method used to identify attack packets."
Which seems to be a reasonable one compared to generating
additional packets in the network(itrace) and having the destination
network suffer from ICMP threats.
My point of discussion here is not to degrade itrace method but to find
out the most efficient way of addressing IP traceback. If anyone has a
view of more problems associated with hash-based ip traceback please let
me know.
D.Rajesh Kumar
e-security Practice
TCS-America,Riverside
Tel: 909-3281980 Ext 13
Fax: 909-3281987