See this document in CiteSeerX!

Large-Scale IP Traceback in High-Speed Internet: Practical Techniques and Theoretical Foundation (2004)  (Make Corrections)  (5 citations)
Jun Li, Minho Sung, Jun (Jim) Xu, Li (Erran) Li



  Home/Search   Context   Related

 
View or download:
gatech.edu/~jx/reprints/IEEESP04.ps
Cached:  PS.gz  PS  PDF   Image  Update  Help

From:  gatech.edu/~jx/ (more)
(Enter author homepages)

Rate this article: (best)
  Comment on this article  
(Enter summary)

Abstract: Tracing attack packets to their sources, known as IP traceback, is an important step to counter distributed denial-of-service (DDoS) attacks. In this paper, we propose a novel packet logging based (i.e., hash-based) traceback scheme that requires an order of magnitude smaller processing and storage cost than the hash-based scheme proposed by Snoeren et al. [29], thereby being able to scalable to much higher link speed (e.g., OC-768). The baseline idea of our approach is to sample and log a... (Update)

Cited by:   More
Flexible Flow Aggregation for Adaptive Network Monitoring - Falko Dressler Autonomic   (Correct)
gore: Routing-Assisted Defense against DDoS Attacks - Chou, Stavrou, Ioannidis..   (Correct)
WebSOS: An Overlay-based System for Protecting Web .. - Stavrou, Cook.. (2005)   (Correct)

Active bibliography (related documents):   More   All
0.9:   IP Traceback-based Intelligent Packet Filtering: A Novel.. - Sung, Xu (2002)   (Correct)
0.7:   Pi: A Path Identification Mechanism to Defend against DDoS.. - Yaar, Perrig, Song (2003)   (Correct)
0.4:   A Scalable Set-Union Counting Approach to Pushing Back DDoS.. - Kwok, Cai, Hwang (2004)   (Correct)

Similar documents based on text:   More   All
0.3:   Data Streaming Algorithms for Efficient and Accurate.. - Kumar, Sung, Xu, Wang (2004)   (Correct)
0.2:   ICMP Traceback with Cumulative Path, An Efficient - Solution For Ip (2003)   (Correct)
0.2:   Space-Code Bloom Filter for Efficient Per-Flow Traffic.. - Kumar, Xu, Wang.. (2004)   (Correct)

Related documents from co-citation:   More   All
4:   Hash-Based IP Traceback - Snoeren, Partridge et al. - 2001
4:   SOS: Secure Overlay Services - Keromytis, Misra et al. - 2002
4:   Implementing Pushback: Router-Based Defense Against DDoS Attacks - Ioannidis, Bellovin - 2002

BibTeX entry:   (Update)

J. Li, M. Sung, J. Xu, L. Li, Large-Scale IP Traceback in High-Speed Internet: Practical Techniques and Theoretical Foundation, in: Proceedings of the IEEE Symposium on Security and Privacy, 2004. http://citeseer.ist.psu.edu/li04largescale.html   More

@misc{ li04largescale,
  author = "J. Li and M. Sung and J. Xu and L. Li",
  title = "Large-Scale IP Traceback in High-Speed Internet: Practical Techniques and
    Theoretical Foundation",
  text = "J. Li, M. Sung, J. Xu, L. Li, Large-Scale IP Traceback in High-Speed Internet:
    Practical Techniques and Theoretical Foundation, in: Proceedings of the
    IEEE Symposium on Security and Privacy, 2004.",
  year = "2004",
  url = "citeseer.ist.psu.edu/li04largescale.html" }
Citations (may not include all citations):
2319   Elements of information theory (context) - Cover, Thomas - 1991
293   Summary cache: A scalable wide-area Web cache sharing protoc.. - Fan, Cao et al. - 2000
154   Network Ingress Filtering: Defeating Denial of Service Attac.. (context) - Ferguson - 1998
148   Practical network support for IP traceback - Savage, Wetherall et al. - 2000
113   Inferring Internet Denial-of-Service activity - Moore, Voelker et al. - 2001
98   SOS: Secure overlay services - Keromytis, Misra et al. - 2002
92   Controlling high bandwidth aggregates in the network - Mahajan, Bellovin et al. - 2002
90   or which way to the information age (context) - Turner, in - 1986
72   An algebraic approach to IP traceback - Dean, Franklin et al. - 2001
70   Hash-based IP traceback - Snoeren, Partridge - 2001
64   in hash coding with allowable errors (context) - Bloom, time - 1970
63   Advanced and authenticated marking schemes for IP traceback - Song, Perrig - 2001
57   Tracing anonymous packets to their approximate source (context) - Burch, Cheswick - 2000
33   Denial-of-service attacks rip the Internet (context) - Garber - 2000
31   A framework for classifying denial of service attacks - Hussain, Heidemann et al. - 2003
16   Protecting web servers from distributed denial of service at.. - Kargl, Maier et al. - 2001
15   Attacking DDoS at the source - Mirkovic, Prier et al. - 2002
13   Defending against distributed denial-of-service attacks with.. - Yau, Lui et al.
12   Using router stamping to identify the source of IP packets (context) - Doeppner, Klein et al. - 2000
9   COSSACK: coordinated suppression of simultaneous attacks (context) - Papadopoulos, Lindell et al. - 2003
8   ectiveness of route-based packet ltering for distributed DoS.. (context) - Park, Lee - 2001
7   IP Traceback-based Intelligent Packet Filtering: A Novel Tec.. - Sung, Xu - 2003
5   in probabilistic packet marking for ip traceback (context) - Adler - 2002
5   Trajectory sampling for direct trac observation (context) - Dueld, Grossglauser - 2000
4   An analysis of using re ectors for distributed denial-of-ser.. (context) - Paxson - 2001
2   Attack on internet called largest ever (context) - McGuire, Krebs - 2002
2   Internet mapping (context) - Cheswick - 1999
1   Sustaining availability of web services under severe denial .. (context) - XuandW - 2003
1   Ecient packet marking for largescale IP traceback (context) - Goodrich - 2002
1   Pi: A path identi - cation mechanism to defend against DDoS .. (context) - Yaar, Perrig et al. - 2003
1   Alliance formation for ddos defense - Mirkovic, Robinson et al. - 2003
1   Detecting SYN ooding attacks (context) - Wang, Zhang et al. - 2002
1   Hop-count ltering: An e ective defense against spoofed DDoS .. (context) - Jin, Wang et al. - 2003
1   Spectral bloom lters (context) - Cohen, Matias - 2003
http://www.caida.org/tools/measurement/skitter/
http://www.snort.org

Documents on the same site (http://www.cc.gatech.edu/~jx/):   More
Cost-Effective Flow Table Designs for High-Speed Routers.. - Xu, Singhal (2002)   (Correct)
Prefix-Preserving IP Address Anonymization.. - Xu, Fan, Ammar, Moon (2002)   (Correct)
Sustaining Availability of Web Services under Distributed Denial.. - Xu, Lee (2002)   (Correct)

Online articles have much greater impact   More about CiteSeer.IST   Add search form to your site   Submit documents   Feedback  

CiteSeer.IST - Copyright Penn State and NEC