Detecting Disruptive Routers: A Distributed Network Monitoring Approach (1998) [50 citations — 1 self]
Abstract:
An attractive target for a computer system attacker is the router. An attacker in control of a router can disrupt communication by dropping or misrouting packets passing through the router. We present a protocol called WATCHERS that detects and reacts to routers that drop or misroute packets. WATCHERS is based on the principle of conservation of ow in a network: all data bytes sent into a node, and not destined for that node, are expected to exit the node. WATCHERS tracks this ow, and detects routers that violate the conservation principle. We show that WATCHERS has several advantages over existing network monitoring techniques. We argue that WATCH-ERS ' impact on router performance and WATCHERS' memory requirements are reasonable for many environments. We demonstrate that in ideal conditions WATCHERS makes no false-positive diagnoses. We also describe how WATCHERS can be tuned to perform nearly as well in realistic conditions. c 1998 IEEE. Personal use of this material is permitted. However, permission to reprint/republish this material for advertising or promotional purposes or for creating new collective works for resale or redistribution to servers or lists, or to reuse any copyrighted component of this work in other works must be obtained from the IEEE. Kirk Bradley's current a liation is SRI International, 333
Citations
| 476 | OSPF version 2 – Moy - 1997 |
| 301 | Internetworking with TCP/IP – Comer - 1991 |
| 252 | Routing in the Internet – Huitema - 1999 |
| 190 | Security problems in the TCP/IP protocol suite – Bellovin - 1989 |
| 162 | Bellovin: Firewalls and Internet Security: Repelling the Wily Hacker – Cheswick, M - 1994 |
| 137 | Network layer protocols with Byzantine robustness – Perlman - 1988 |
| 63 | A Simple Network Management Protocol (SNMP – Case, Fedor, et al. - 1990 |
| 53 | Routing in Communications Networks – Steenstrup - 1995 |
| 44 | A Simple Active Attack Against TCP – Joncheray - 1995 |
| 40 | Protecting routing infrastructure from denial of service using cooperative intrusion detection – Cheung, Levitt - 1997 |
| 15 | Network Management Standards – Black - 1994 |
| 3 | Setting Optimal IntrusionDetection Thresholds – Soh, Dillon - 1995 |
| 1 | AN Management with SNMP and RMON – Held - 1996 |

