1: \begin{abstract}
2: Multiple \textit{probabilistic packet marking} (PPM) schemes for IP
3: traceback have been proposed to deal with \textit{Distributed Denial
4: of Service} (DDoS) attacks by reconstructing their attack graphs and
5: identifying the attack sources.
6:
7: In this paper, ten PPM-based IP traceback schemes are compared and
8: analyzed in terms of features such as convergence time, performance
9: evaluation, underlying topologies, incremental deployment, re-marking,
10: and upstream graph. Our analysis shows that the considered schemes
11: exhibit a significant discrepancy in performance as well as performance
12: assessment. We concisely demonstrate this by providing a table showing
13: that (a) different metrics are used for many schemes to measure their
14: performance and, (b) most schemes are evaluated on different classes
15: of underlying network topologies.
16:
17: Our results reveal that both the value and arrangement of the PPM-based
18: scheme convergence times vary depending on exactly the underlying
19: network topology. As a result, this paper shows that a side-by-side
20: comparison of the scheme performance a complicated and turns out to
21: be a crucial open problem in this research area.
22:
23: \medskip{}
24: \end{abstract}
25: