FDPM: Scaling IP Traceback to 100,000+ Attack Sources without Crippling Routers

Flexible Deterministic Packet Marking: An IP Traceback System to Find the Real Source of Attacks

2008-08-18
Yang Xiang, Wanlei Zhou, Minyi Guo
Summary
Problem
Method
Results
Takeaways
Abstract

The paper introduces Flexible Deterministic Packet Marking (FDPM), a scalable IP traceback system designed to identify the real sources of DDoS attacks. FDPM achieves state-of-the-art performance by supporting flexible mark lengths and an adaptive flow-based marking rate, allowing it to trace up to 10^5 sources in a single process.

Executive Summary

TL;DR: FDPM (Flexible Deterministic Packet Marking) is a robust IP traceback system that solves the "who and where" of DDoS attacks. By dynamically adjusting both the length of marks and the rate of marking based on router load, it can trace a massive number of sources (10^5) with minimal impact on network throughput.

Historically, IP traceback has been a trade-off between accuracy and performance. FDPM breaks this stalemate, positioning itself as a practical, deployable solution for modern ISP-scale infrastructures that require high-speed packet forwarding and forensic accountability.

The Bottleneck of Anonymous Traffic

The Internet is stateless by design. Attackers exploit this by spoofing source IP addresses, making it nearly impossible for victims to find the true origin of a DDoS flood. Prior attempts like Probabilistic Packet Marking (PPM) required thousands of packets and days of computation to reconstruct paths, while early Deterministic Packet Marking (DPM) methods were rigid, frequently leading to hash collisions and router performance degradation.

The authors identify a critical missing link: Overload Prevention. If a security mechanism slows down the router during an attack (when the router is already stressed), the defense itself becomes a vulnerability.

Methodology: Flexibility as a Core Virtue

FDPM’s architecture is built on two pillars of flexibility:

1. Flexible Mark Length (Compatibility)

Depending on the network environment, FDPM utilizes different bits within the IPv4 header (TOS, Fragment ID, and Reserved Flag). It can adapt between 24-bit, 19-bit, or 16-bit marks. This ensures that even if certain protocols require the TOS field, FDPM can still function by shrinking its fingerprint.

FDPM Encoding Strategy

2. Flow-Based Marking (Intelligence)

Unlike "dumb" marking schemes that process every packet, FDPM monitors router load. When CPU or throughput thresholds are breached, it switches to a Flow-Based strategy. It uses a FIFO queue and EWMA (Exponentially Weighted Moving Average) to identify high-bandwidth flows—the primary characteristic of DDoS—and shifts marking priority toward those packets.

Performance: SOTA Results

The experimental results, validated via both SSFNet simulations and real-world implementation on Click modular routers, are compelling:

  • Traceback Capacity: While standard DPM can trace roughly 2,000 sources, FDPM-24 handles over 100,000 in a single process.
  • Forwarding Efficiency: In high-load scenarios, FDPM's intelligent marking keeps the maximum forwarding rate significantly higher than traditional "mark-all" approaches.

Forwarding Rate Comparison

The chart above illustrates that FDPM's flow-based mechanism (top curve) preserves the router's ability to handle traffic far better than a scheme that forces marking on every packet (bottom curve).

Deep Insight & Conclusion

The genius of FDPM lies not just in its encoding math, but in its recognition that security must be elastic. By treating packet marking as a resource-constrained task, FDPM allows routers to maintain Inductive Bias toward attacking flows while ignoring the "noise" of legitimate, low-volume traffic.

Takeaway: Future network security protocols cannot afford to be static. The ability to adapt to protocol constraints and hardware load is what transforms a theoretical algorithm into a practical defense system. While FDPM focuses on IPv4, its flow-based logic remains a foundational blueprint for protecting high-speed backbones against ever-evolving volumetric threats.

Find Similar Papers

Try Our Examples

  • Search for recent IP traceback papers that utilize IPv6 extension headers instead of overloading IPv4 header fields.
  • Which paper first introduced the concept of Deterministic Packet Marking (DPM), and how does FDPM's digest mechanism differ from the original DPM proposal?
  • Investigate if there are current studies applying the FDPM flow-based marking logic to Machine Learning-based DDoS detection systems at the edge.
Contents
FDPM: Scaling IP Traceback to 100,000+ Attack Sources without Crippling Routers
1. Executive Summary
2. The Bottleneck of Anonymous Traffic
3. Methodology: Flexibility as a Core Virtue
3.1. 1. Flexible Mark Length (Compatibility)
3.2. 2. Flow-Based Marking (Intelligence)
4. Performance: SOTA Results
5. Deep Insight & Conclusion