To defend the IP spoofing and differentiate IP address in the network intrusion detection system and DDoS defense system, we give a novel approach Recursion Nearness to characterize the IP address features, which is also helpful to the other security applications, such as firewall log analysis, traffics filter rule management, intrusion investigation and IP trace back. We characterize the IP address with some fields, such as TTL, MAC, TCP/IP stack implementation fingerprinting and IP geographic location mapping. Major implementation approaches to the system are discussed and given. Experiment results of our system show that this method can characterize IP features more exact and efficiently.
Citation:
Wei Ren, Hai Jin, "A Recursion Nearness Based Method for Characterizing IP Address," pdcat, pp.665-669, Sixth International Conference on Parallel and Distributed Computing Applications and Technologies (PDCAT'05), 2005