Layer 2 traceback is an important component of end-toend packet traceback. Whilst IP traceback identifies the origin network, L2 traceback extends the process to provide a more fine-grained result. Other known proposals have exposed the difficulties of L2 traceback in switched ethernet. We build on our earlier work and improve in a number of dimensions. Memory requirements are decreased by maintaining ‘connection records’ rather than logging all frames. Our switchport resolution algorithm provides error detection by correlating MAC-table values from two switches. Furthermore, our solution takes stock of potential transformations to packet data as this leaves the local network.
Marios S. Andreou, Aad P. A. van Moorsel