Thank you for being a valued part of the CNET community. As of December 1, 2020, the forums are in read-only format. In early 2021, CNET Forums will no longer be available. We are grateful for the participation and advice you have provided to one another over the years.

Thanks,

CNET Support

Question

Tracebacking the IP packets

Nov 3, 2015 10:10AM PST

Is it possible to traceback any IP packet for its source assuming it is a legitimate packet and not spoofed??

Discussion is locked

- Collapse -
Answer
Most of the time?
Nov 3, 2015 10:23AM PST

You won't know till you try it. Many will end at some router and you can't go through that gateway. Frankly it's mostly a waste of time. Better to block that IP and be done with it.

- Collapse -
thanks for reply
Nov 14, 2015 4:18AM PST

Yeah, I know that the routers have features to not to provide their owner source to any other party. But my interest is to check the status of connection for a Packet! Suppose if someone sent me a packet and I want to check whether that source is still connected or not! So basically I will ping to source IP and wait for reply. Now here I am a little bit in trouble with IP extraction from a packet. Anyway thanks for reply.

- Collapse -
Answer
Tracebacking IP Packets
Nov 11, 2015 6:23AM PST

Unfortunately the nature of the IP protocol makes it extremely difficult to dependably identify the origin of an IP packet. While a variety of techniques have been created to identify the source of a large number packet flows, techniques have not yet been developed to track individual packets. As was recommended above, I suggest simply blocking this IP, as it could cause harm to your network.

- Collapse -
thanks for reply
Nov 14, 2015 4:20AM PST

Hmmm....Can you provide me illustrated examples for describing those source identification techniques of a large number of packet flow?