Abstract-Cybercrime has become an important issue in the cyber-society. Distributed Denial of Service attack is the most popular attack, which uses many zombies to attack the victim, makes victim crashed and interrupt services. We propose the LT Code IP Traceback scheme to reconstruct the attack graph and find the source of attacker. LTCIP overcomes the collision problem in traditional packet marking scheme. It uses fewer packets to reconstruct the attack graph. Finally, our LTCIP is a reliable IP Traceback scheme, which can find the source of DDoS and avoid the attack Index Terms-IP Traceback, DDoS attack, Packet Marking, Network Forensics