See this document in CiteSeerX!

IP Traceback-based Intelligent Packet Filtering: A Novel Technique for Defending against Internet DDoS Attacks (2002)  (Make Corrections)  (7 citations)
Minho Sung, Jun Xu
IEEE Transactions on Parallel and Distributed Systems



  Home/Search   Context   Related

 
View or download:
gatech.edu/~jx/reprints/ICNP02B.ps
Cached:  PS.gz  PS  PDF   Image  Update  Help

From:  gatech.edu/~jx/ (more)
Homepages:  J.Xu  

Rate this article: (best)
  Comment on this article  
(Enter summary)

Abstract: Distributed Denial of service (DDoS) is one of the most difficult security problems to address. While many existing techniques (e.g., IP traceback) focus on tracking the location of the attackers after-the-fact, little is done to mitigate the effect of an attack while it is raging on. In this paper, we present a novel technique that can effectively filter out the majority of DDoS traffic, thus improving the overall throughput of the legitimate traffic. The proposed scheme leverages on and... (Update)

Cited by:   More
A Scalable Set-Union Counting Approach to Pushing Back DDoS.. - Kwok, Cai, Hwang (2004)   (Correct)
Perimeter-Based Defense against High Bandwidth DDoS Attacks - Chen, Song (2005)   (Correct)
IP Easy-pass: Edge Resource Access Control - Wang, Bose, El-Gendy, Shin (2004)   (Correct)

Active bibliography (related documents):   More   All
2.1:   Sustaining Availability of Web Services under Distributed Denial.. - Xu, Lee (2002)   (Correct)
0.9:   Large-Scale IP Traceback in High-Speed Internet: Practical.. - Li, Sung, Xu, Li (2004)   (Correct)
0.3:   Random Flow Network Modeling and Simulations for.. - Kong, Mirza, Shu, .. (2003)   (Correct)

Similar documents based on text:   More   All
0.4:   Defending Wireless Infrastructure against the Challenge of .. - Geng, Huang, Whinston (2002)   (Correct)
0.4:   Mobile Networks and Applications 7, 213--223, 2002 - Defending Wireless..   (Correct)
0.3:   Protection from Distributed Denial of Service Attack.. - Peng, Leckie.. (2003)   (Correct)

Related documents from co-citation:   More   All
7:   Inferring Internet Denial-of-Service Activity - Moore, Voelker et al. - 2001
6:   Network Ingress Filtering: Defeating Denial of Service Attacks which Employ IP S.. (context) - Ferguson, Senie - 1998
5:   Pi: A Path Identification Mechanism to Defend against DDoS Attacks - Yaar, Perrig et al. - 2003

BibTeX entry:   (Update)

M. Sung and J. Xu. IP Traceback-based Intelligent Packet Filtering: A Novel Technique for Defending Against Internet DDoS Attacks. IEEE Transactions on Parallel and Distributed Systems, 14(9):861-872, Sept. 2003. Preliminary version appeared in Proc. 10th IEEE ICNP. http://citeseer.ist.psu.edu/sung02ip.html   More

@article{ sung03ip,
  author = "M. Sung and J. Xu",
  title = "IP Traceback-based Intelligent Packet Filtering: A Novel Technique for
    Defending Against Internet {DDoS} Attacks",
  journal = "IEEE Transactions on Parallel and Distributed Systems", 
  volume = "14",
  number = "9",
  pages = "861--872",
  month = sep,
  year = "2003",
  url = "citeseer.ist.psu.edu/sung02ip.html" }
Citations (may not include all citations):
154   Network Ingress Filtering: Defeating Denial of Service Attac.. (context) - Ferguson - 1998
148   Practical network support for ip traceback - Savage, Wetherall et al. - 2000
92   Controlling high bandwidth aggregates in the network - Mahajan, Bellovin et al. - 2001
78   Analysis of a denial of service attack on tcp - Schuba - 1997
74   Photuris: Session-Key Management Protocol (context) - Karn, Simpson - 1999
72   An algebraic approach to ip traceback - Dean, Franklin et al. - 2001
70   Hash-based ip traceback - Snoeren, Partridge - 2001
64   in hash coding with allowable errors (context) - Bloom, time - 1970
63   Advanced and authenticated marking schemes for ip traceback - Song, Perrig - 2001
57   Tracing anonymous packets to their approximate source (context) - Burch, Cheswick - 2000
50   An Analysis of Security Incidents on the Internet (context) - Howard - 1998
33   Client puzzles: A cryptographic countermeasure against conne.. (context) - Juels, Brainard - 1999
33   Denial-of-service attacks rip the internet (context) - Garber - 2000
16   Protecting web servers from distributed denial of service at.. - Kargl, Maier et al. - 2001
12   Using router stamping to identify the source of ip packets (context) - Doeppner, Klein et al. - 2000
8   ectiveness of route-based packet ltering for distributed dos.. (context) - Park, Lee - 2001
3   Internet draft: Icmp traceback messages (context) - Bellovin - 2000
3   Defending Against Distributed Denialof -Service Attacks with.. (context) - Yau, Lui et al. - 2002
2   Internet mapping (context) - Cheswick - 1999
2   Sustaining availability of web services under severe denial .. (context) - Xu, Lee - 2003
2   Tcp syn ooding attack and the rewall-1 syndefender (context) - Inc - 1997
http://www.akamai.com/
http://www.caida.org/Tools/Skitter/



The graph only includes citing articles where the year of publication is known.


Documents on the same site (http://www.cc.gatech.edu/~jx/):   More
Cost-Effective Flow Table Designs for High-Speed Routers.. - Xu, Singhal (2002)   (Correct)
Prefix-Preserving IP Address Anonymization.. - Xu, Fan, Ammar, Moon (2002)   (Correct)
Sustaining Availability of Web Services under Distributed Denial.. - Xu, Lee (2002)   (Correct)

Online articles have much greater impact   More about CiteSeer.IST   Add search form to your site   Submit documents   Feedback  

CiteSeer.IST - Copyright Penn State and NEC