A Technique for Network Topology Deception

Samuel T. Trassare, Robert Beverly, David Alderson
2013 MILCOM 2013 - 2013 IEEE Military Communications Conference  
Active Network Topology Measurement traceroute and its variants source active TTL-limited probes to infer (remote) network connectivity and structure. traceroute reports hops along a forward path based on the source IP address of received ICMP TTL time exceeded packets. Useful diagnostic tool, invaluable to network topology researchers. Recall: traceroute is a happy hack (thanks Van Jacobson!). Internet never intended to be mapped. S. Trassare et al. (NPS) A Technique for Network Topology
more » ... ion NPS Topo Mtg 3 / 23 Background traceroute in Practice Real-world traceroute: For security, policy, and economic reasons, many providers actively prevent traceroute measurement Many routers do not respond with ICMP when TTL expires Many routers block ICMP In real-world traces, only ≤ 15% of random traces complete. S. Trassare et al. (NPS) A Technique for Network Topology Deception NPS Topo Mtg 4 / 23 Background traceroute in Practice Real-world traceroute: Long history of bad topology inferences by researchers e.g. false links, missing links, etc. "What are our standards for validation of measurement-based networking research?" (Krishnamurthy, Willinger) "Mathematics and the Internet: A source of enormous confusion and great potential" (Willinger, Alderson, Doyle) Candidate test topology in our lab (using GNS3) S. Trassare et al. (NPS) A Technique for Network Topology Deception NPS Topo Mtg 15 / 23 Results True Topology traceroute
doi:10.1109/milcom.2013.303 dblp:conf/milcom/TrassareBA13 fatcat:nvam6quksrbdtguhflzfrfi3mu