(Enter summary)
Abstract: Distributed Denial of service (DDoS) is one of the most difficult security problems to address. While many existing techniques (e.g., IP traceback) focus on tracking the location of the attackers after-the-fact, little is done to mitigate the effect of an attack while it is raging on. In this paper, we present a novel technique that can effectively filter out the majority of DDoS traffic, thus improving the overall throughput of the legitimate traffic. The proposed scheme leverages on and... (Update)
Cited by: More
A Scalable Set-Union Counting Approach to Pushing Back DDoS.. - Kwok, Cai, Hwang (2004)
(Correct)
Perimeter-Based Defense against High Bandwidth DDoS Attacks - Chen, Song (2005)
(Correct)
IP Easy-pass: Edge Resource Access Control - Wang, Bose, El-Gendy, Shin (2004)
(Correct)
Active bibliography (related documents): More All
2.1: Sustaining Availability of Web Services under Distributed Denial.. - Xu, Lee (2002)
(Correct)
0.9: Large-Scale IP Traceback in High-Speed Internet: Practical.. - Li, Sung, Xu, Li (2004)
(Correct)
0.3: Random Flow Network Modeling and Simulations for.. - Kong, Mirza, Shu, .. (2003)
(Correct)
Similar documents based on text: More All
0.4: Defending Wireless Infrastructure against the Challenge of .. - Geng, Huang, Whinston (2002)
(Correct)
0.4: Mobile Networks and Applications 7, 213--223, 2002 - Defending Wireless..
(Correct)
0.3: Protection from Distributed Denial of Service Attack.. - Peng, Leckie.. (2003)
(Correct)
Related documents from co-citation: More All
7: Inferring Internet Denial-of-Service Activity
- Moore, Voelker et al. - 2001
6: Network Ingress Filtering: Defeating Denial of Service Attacks which Employ IP S.. (context) - Ferguson, Senie - 1998
5: Pi: A Path Identification Mechanism to Defend against DDoS Attacks
- Yaar, Perrig et al. - 2003
BibTeX entry: (Update)
M. Sung and J. Xu. IP Traceback-based Intelligent Packet Filtering: A Novel Technique for Defending Against Internet DDoS Attacks. IEEE Transactions on Parallel and Distributed Systems, 14(9):861-872, Sept. 2003. Preliminary version appeared in Proc. 10th IEEE ICNP. http://citeseer.ist.psu.edu/sung02ip.html More
@article{ sung03ip,
author = "M. Sung and J. Xu",
title = "IP Traceback-based Intelligent Packet Filtering: A Novel Technique for
Defending Against Internet {DDoS} Attacks",
journal = "IEEE Transactions on Parallel and Distributed Systems",
volume = "14",
number = "9",
pages = "861--872",
month = sep,
year = "2003",
url = "citeseer.ist.psu.edu/sung02ip.html" }
Citations (may not include all citations):
154
Network Ingress Filtering: Defeating Denial of Service Attac.. (context) - Ferguson - 1998
148
Practical network support for ip traceback
- Savage, Wetherall et al. - 2000
92
Controlling high bandwidth aggregates in the network
- Mahajan, Bellovin et al. - 2001
78
Analysis of a denial of service attack on tcp
- Schuba - 1997
74
Photuris: Session-Key Management Protocol (context) - Karn, Simpson - 1999
72
An algebraic approach to ip traceback
- Dean, Franklin et al. - 2001
70
Hash-based ip traceback
- Snoeren, Partridge - 2001
64
in hash coding with allowable errors (context) - Bloom, time - 1970
63
Advanced and authenticated marking schemes for ip traceback
- Song, Perrig - 2001
57
Tracing anonymous packets to their approximate source (context) - Burch, Cheswick - 2000
50
An Analysis of Security Incidents on the Internet (context) - Howard - 1998
33
Client puzzles: A cryptographic countermeasure against conne.. (context) - Juels, Brainard - 1999
33
Denial-of-service attacks rip the internet (context) - Garber - 2000
16
Protecting web servers from distributed denial of service at..
- Kargl, Maier et al. - 2001
12
Using router stamping to identify the source of ip packets (context) - Doeppner, Klein et al. - 2000
8
ectiveness of route-based packet ltering for distributed dos.. (context) - Park, Lee - 2001
3
Internet draft: Icmp traceback messages (context) - Bellovin - 2000
3
Defending Against Distributed Denialof -Service Attacks with.. (context) - Yau, Lui et al. - 2002
2
Internet mapping (context) - Cheswick - 1999
2
Sustaining availability of web services under severe denial .. (context) - Xu, Lee - 2003
2
Tcp syn ooding attack and the rewall-1 syndefender (context) - Inc - 1997
http://www.akamai.com/
http://www.caida.org/Tools/Skitter/
The graph only includes citing articles where the year of publication is known.
Documents on the same site (http://www.cc.gatech.edu/~jx/): More
Cost-Effective Flow Table Designs for High-Speed Routers.. - Xu, Singhal (2002)
(Correct)
Prefix-Preserving IP Address Anonymization.. - Xu, Fan, Ammar, Moon (2002)
(Correct)
Sustaining Availability of Web Services under Distributed Denial.. - Xu, Lee (2002)
(Correct)
Online articles have much greater impact More about CiteSeer.IST Add search form to your site Submit documents Feedback
CiteSeer.IST - Copyright Penn State and NEC