Abstract. With the help of real source identity in packets, network security system can intelligently protect and counteract the attacks. Packet marking is an important method of source identification, and there are some issues on it. For large amount of packets, analysis time and complicated computation are necessary while detect marking information. This paper focuses on this direction, and proposes a simple and efficient method to mark all packets belonging to upstream traffic with a deterministic, plain form identity. With this approach, we just need low processing power on some specific edge routers as well as a little extra network traffic to settle it. Furthermore, distilling mark from packets is easy since the mark is in plain text format.