Traceback of DDoS Attacks: Why Information Entropy is the Ultimate Weapon
TRACEBACK OF DDOS ATTACKS USING ENTROPY VARIATIONS
The paper introduces a novel IP traceback method for DDoS attacks based on "entropy variations," which measures changes in traffic randomness at routers. By identifying significant drops in flow entropy during an attack, the system can parallelly push back and locate thousands of zombies in large-scale networks without modifying existing IP packet headers.
TL;DR
The stateless nature of the Internet makes identifying DDoS sources nearly impossible without complex "marking" schemes that are easily fooled. This paper proposes a breakthrough: using Entropy Variations to track the "randomness footprint" of attack flows. By observing how entropy drops as attack traffic aggregates, defenders can trace back to thousands of zombies in under 20 seconds—no packet marking required.
The "Memoryless" Problem and the Failure of Marking
The Internet was designed to be stateless. A router receives a packet, looks at the destination, and passes it on—it doesn't remember where it came from. When a victim is flooded by a DDoS attack, they see the "what" (malicious packets) but never the "who" (the actual zombies).
Prior solutions like Probabilistic Packet Marking (PPM) and Deterministic Packet Marking (DPM) tried to force "memory" into the network by injecting router IDs into the small, unused bits of IP headers. This failed because:
- Scalability: There aren't enough bits in an IPv4 header to store deep path info.
- Pollution: Attackers can spoof these marks, "polluting" the traceback data.
- Inertia: Requiring every router on Earth to update its software is a non-starter.
The Insight: Entropy as a Signal
The authors propose a radical shift: Stop looking at the packets, starts looking at the flow behavior.
In a healthy network, traffic is diverse and "random," leading to high entropy. When an attacker launches a flooding attack, they inject a massive, highly structured stream of packets toward a single destination. This act destroys the local entropy at every router the traffic passes through.
The Core Mechanism: Entropy Variation Convergence
As attack flows move toward the victim, they aggregate. The closer a router is to the victim, the more the attack traffic dominates the local flow distribution, causing the entropy to plunge.
Figure 1: A sample network showing how the victim initiates the pushback process based on localized entropy knowledge.
Methodology: The Pushback Algorithm
The system operates in two phases:
- Passive Monitoring: In non-attack periods, routers record the "mean" and "standard deviation" of flow entropy. This creates a baseline of what "normal randomness" looks like.
- Active Pushback: Once an attack is detected, the victim sends a request to its immediate upstream routers. Those routers check: "Is my current entropy significantly lower than my baseline?" If yes, they identify which upstream interface is supplying the "entropy-killing" traffic and pass the request further up the tree.
Performance Comparison
The beauty of this method lies in its efficiency. Unlike packet logging, which requires gigabytes of storage, entropy variation only requires counting packet numbers—a trivial task for modern hardware.
| Metric | DPM | PPM | Entropy Variation |
|---|---|---|---|
| Scalability | Medium | Low | Very High |
| Storage | Very High | High | Very Low (~240k/min) |
| Traceback Time | Low | Medium | Low (Real-time) |
Experimental Proof: Speed and Accuracy
The authors' simulations show that the entropy drop is almost linear relative to attack strength. Importantly, they discovered a "discrimination limit": as long as the attack traffic is at least 7 times stronger than legitimate traffic, the traceback is highly accurate.
Figure 2: The sharp drop in entropy as attack strength increases, allowing for clear detection.
In a worst-case scenario with 1,024 zombies located 30 hops away, the system successfully identified the sources in just 25 seconds.
Figure 3: Total traceback time remains well below the average 5-10 minute window of typical DDoS attacks.
Critical Analysis & Conclusion
Takeaway
This method solves the "header bit" problem by moving the logic out of the packet and into the router's monitoring plane. It is immune to "packet pollution" because attackers cannot "spoof" the fact that they are sending a massive volume of packets—the very act of the attack is what creates the signal.
Limitations
- Flash Crowds: The method might struggle to distinguish a DDoS attack from a "Flash Crowd" (legitimate spike in interest), as both involve a surge in traffic to one destination.
- Low-Volume Attacks: If an attacker sends traffic at a rate lower than 7x the normal flow, the "entropy signal" becomes too noisy to track reliably.
Future Outlook
The next frontier is combining this entropy approach with Machine Learning to help differentiate between "malicious structure" and "legitimate surges," potentially neutralizing even the most subtle, low-rate DDoS attacks.
