{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,24]],"date-time":"2025-03-24T06:57:43Z","timestamp":1742799463639},"reference-count":48,"publisher":"Elsevier BV","issue":"8","license":[{"start":{"date-parts":[[2008,6,1]],"date-time":"2008-06-01T00:00:00Z","timestamp":1212278400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/www.elsevier.com\/tdm\/userlicense\/1.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Computer Networks"],"published-print":{"date-parts":[[2008,6]]},"DOI":"10.1016\/j.comnet.2007.11.023","type":"journal-article","created":{"date-parts":[[2008,3,7]],"date-time":"2008-03-07T20:25:41Z","timestamp":1204921541000},"page":"1567-1582","source":"Crossref","is-referenced-by-count":9,"title":["Packet forwarding with source verification"],"prefix":"10.1016","volume":"52","author":[{"given":"Craig A.","family":"Shue","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Minaxi","family":"Gupta","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Matthew P.","family":"Davy","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"78","reference":[{"key":"10.1016\/j.comnet.2007.11.023_bib1","unstructured":"R. Beverly, S. Bauer, The spoofer project: inferring the extent of Internet source address filtering on the Internet, USENIX Workshop on Steps to Reduce Unwanted Traffic in the Internet (SRUTI), 2005."},{"key":"10.1016\/j.comnet.2007.11.023_bib2","doi-asserted-by":"crossref","unstructured":"D. Moore, G. Voelker, S. Savage, Inferring internet denial-of-service activity, in: USENIX Security Symposium, 2001.","DOI":"10.21236\/ADA400003"},{"issue":"2","key":"10.1016\/j.comnet.2007.11.023_bib3","doi-asserted-by":"crossref","first-page":"115","DOI":"10.1145\/1132026.1132027","article-title":"Inferring internet denial-of-service activity","volume":"24","author":"Moore","year":"2006","journal-title":"ACM Transactions on Computer Systems (TOCS)"},{"key":"10.1016\/j.comnet.2007.11.023_bib4","unstructured":"J. Connelly, SUMI: a fast anonymous file transfer program website, <https:\/\/2.zoppoz.workers.dev:443\/http\/sumi.berlios.de\/wiki\/MainPage>."},{"key":"10.1016\/j.comnet.2007.11.023_bib5","unstructured":"RODI, Rodi website, <https:\/\/2.zoppoz.workers.dev:443\/http\/rodi.sourceforge.net\/>."},{"key":"10.1016\/j.comnet.2007.11.023_bib6","unstructured":"S. Bellovin, M. Leech, T. Taylor, ICMP traceback messages, IETF Draft, October 2001."},{"issue":"2","key":"10.1016\/j.comnet.2007.11.023_bib7","doi-asserted-by":"crossref","first-page":"119","DOI":"10.1145\/505586.505588","article-title":"An algebraic approach to IP traceback","volume":"5","author":"Dean","year":"2002","journal-title":"ACM Transactions on Information and System Security"},{"key":"10.1016\/j.comnet.2007.11.023_bib8","doi-asserted-by":"crossref","unstructured":"M. Goodrich, Efficient packet marking for large-scale IP traceback, in: ACM Conference on Computer and Communications Security (CCS), 2001.","DOI":"10.1145\/586110.586128"},{"key":"10.1016\/j.comnet.2007.11.023_bib9","unstructured":"J. Li, M. Sung, J. Xu, L. Li, Large-scale IP traceback in highspeed Internet: practical techniques and theoretical foundations, in: IEEE Symposium on Security and Privacy, May 2004."},{"key":"10.1016\/j.comnet.2007.11.023_bib10","doi-asserted-by":"crossref","unstructured":"S. Savage, D. Wetherall, A. Karlin, T. Anderson, Practical network support for IP traceback, in: ACM SIGCOMM, August 2000.","DOI":"10.1145\/347059.347560"},{"key":"10.1016\/j.comnet.2007.11.023_bib11","doi-asserted-by":"crossref","unstructured":"A. Snoeren, C. Partridge, L. Sanchez, C. Jones, F. Tchakountio, S. Kent, W. Strayer, Hash-based IP traceback, in: ACM SIGCOMM, 2001.","DOI":"10.1145\/383059.383060"},{"key":"10.1016\/j.comnet.2007.11.023_bib12","unstructured":"A. Yaar, A. Perrig, D. Song, FIT: fast internet traceback, in: IEEE INFOCOM, 2005."},{"key":"10.1016\/j.comnet.2007.11.023_bib13","unstructured":"Configuring TCP intercept, <https:\/\/2.zoppoz.workers.dev:443\/http\/www.cisco.com\/univercd\/cc\/td\/doc\/product\/software\/ios113ed\/113edcr\/securc\/scprt3\/scdenial.htm#xtocid254812\/>."},{"key":"10.1016\/j.comnet.2007.11.023_bib14","unstructured":"H. Lee, K. Park, On the effectiveness of probabilistic packet marking for IP traceback under denial of service attack, in: IEEE INFOCOM, April 2001."},{"key":"10.1016\/j.comnet.2007.11.023_bib15","doi-asserted-by":"crossref","unstructured":"C. Jin, H. Wang, K. Shin, Hop-count filtering: an effective defense against spoofed DDoS traffic, in: ACM Conference on Computer and Communications Security (CCS), 2003.","DOI":"10.1145\/948109.948116"},{"key":"10.1016\/j.comnet.2007.11.023_bib16","unstructured":"A. Yaar, A. Perrig, D. Song, Pi: a path identification mechanism to defend against DDoS attacks, in: IEEE Symposium on Security and Privacy, 2003."},{"key":"10.1016\/j.comnet.2007.11.023_bib17","unstructured":"A. Bremler-Barr, H. Levy, Spoofing prevention method, in: IEEE INFOCOM, 2005."},{"key":"10.1016\/j.comnet.2007.11.023_bib18","doi-asserted-by":"crossref","unstructured":"P. Ferguson, D. Senie, Network ingress filtering: defeating denial of service attacks which employ IP source address spoofing, IETF RFC 2827, May 2000, updated by RFC 3704.","DOI":"10.17487\/rfc2827"},{"key":"10.1016\/j.comnet.2007.11.023_bib19","doi-asserted-by":"crossref","unstructured":"F. Baker, P. Savola, Ingress filtering for multihomed networks, IETF RFC 3704, March 2004.","DOI":"10.17487\/rfc3704"},{"key":"10.1016\/j.comnet.2007.11.023_bib20","unstructured":"Configuring Unicast Reverse Path Forwarding, Cisco Systems, March 2004."},{"key":"10.1016\/j.comnet.2007.11.023_bib21","unstructured":"Unicast Reverse Path Forwarding Enhancements for the Internet Service Provider-Internet Service Provider Network Edge, Cisco Systems, 2005."},{"key":"10.1016\/j.comnet.2007.11.023_bib22","unstructured":"J. Li, J. Mirkovic, M. Wang, P. Reiher, L. Zhang, SAVE: source address validity enforcement protocol, in: IEEE INFOCOM, 2002."},{"key":"10.1016\/j.comnet.2007.11.023_bib23","unstructured":"X. Liu, X. Yang, D. Wetherall, T. Anderson, Efficient and secure source authentication with packet passports, in: USENIX Workshop on Steps to Reduce Unwanted Traffic in the Internet (SRUTI), 2006."},{"key":"10.1016\/j.comnet.2007.11.023_bib24","doi-asserted-by":"crossref","unstructured":"G. Malkin, Traceroute using an IP option, IETF RFC 1393 (Experimental), January 1993.","DOI":"10.17487\/rfc1393"},{"key":"10.1016\/j.comnet.2007.11.023_bib25","unstructured":"Georgia Tech Internetwork Topology Models, <https:\/\/2.zoppoz.workers.dev:443\/http\/www.cc.gatech.edu\/projects\/gtitm\/>."},{"key":"10.1016\/j.comnet.2007.11.023_bib26","unstructured":"C.A. for Internet Data Analysis (CAIDA), Skitter project website, 2005, <https:\/\/2.zoppoz.workers.dev:443\/http\/www.caida.org\/tools\/measurement\/skitter\/>."},{"issue":"4","key":"10.1016\/j.comnet.2007.11.023_bib27","doi-asserted-by":"crossref","first-page":"582","DOI":"10.1109\/49.839934","article-title":"Secure border gateway protocol (S-BGP)","volume":"18","author":"Kent","year":"2000","journal-title":"IEEE Journal on Selected Areas in Communications"},{"key":"10.1016\/j.comnet.2007.11.023_bib28","doi-asserted-by":"crossref","unstructured":"R. Chandra, P. Traina, BGP communities attribute, IETF RFC 1997 (Proposed Standard), August 1996.","DOI":"10.17487\/rfc1997"},{"key":"10.1016\/j.comnet.2007.11.023_bib29","doi-asserted-by":"crossref","unstructured":"S. Sangli, D. Tappan, Y. Rekhter, BGP extended communities attribute, IETF RFC 4360 (Proposed Standard), February 2006.","DOI":"10.17487\/rfc4360"},{"key":"10.1016\/j.comnet.2007.11.023_bib30","doi-asserted-by":"crossref","unstructured":"T. Li, B. Cole, P. Morton, D. Li, Cisco Hot Standby Router Protocol (HSRP), IETF RFC 2281, March 1998.","DOI":"10.17487\/rfc2281"},{"issue":"5","key":"10.1016\/j.comnet.2007.11.023_bib31","first-page":"41","article-title":"End-to-end routing behavior in the internet","volume":"36","author":"Paxson","year":"1997","journal-title":"IEEE Transactions of Networking"},{"issue":"1","key":"10.1016\/j.comnet.2007.11.023_bib32","doi-asserted-by":"crossref","DOI":"10.1145\/1052812.1052823","article-title":"An analysis of TCP reset behaviour on the internet","volume":"35","author":"Arlitt","year":"2005","journal-title":"ACM SIGCOMM Computer Communication Review"},{"key":"10.1016\/j.comnet.2007.11.023_bib33","unstructured":"D.J. Bernstein, Syn cookies, 1997, <https:\/\/2.zoppoz.workers.dev:443\/http\/cr.yp.to\/syncookies.html>."},{"key":"10.1016\/j.comnet.2007.11.023_bib34","unstructured":"Y. He, M. Faloutsos, S. Krishnamurthy, Quantifying routing asymmetry in the internet at the AS level, in: IEEE GLOBECOM, 2004."},{"key":"10.1016\/j.comnet.2007.11.023_bib35","unstructured":"CIDR report, <https:\/\/2.zoppoz.workers.dev:443\/http\/www.cidr-report.org\/>."},{"key":"10.1016\/j.comnet.2007.11.023_bib36","unstructured":"L. Subramanian, V. Roth, I. Stoica, S. Shenker, R.H. Katz, Listen and whisper: security mechanisms for BGP, USENIX Symposium on Networked Systems Design and Implementation (NSDI), 2004."},{"key":"10.1016\/j.comnet.2007.11.023_bib37","doi-asserted-by":"crossref","unstructured":"Y. Hu, A. Perrig, M. Sirbu, SPV: secure path vector routing for securing BGP, ACM SIGCOMM, 2004.","DOI":"10.1145\/1015467.1015488"},{"key":"10.1016\/j.comnet.2007.11.023_bib38","unstructured":"T. Wan, E. Kranakis, P. van Oorschot, Pretty secure BGP (psBGP), Internet Society Network and Distributed System Security Symposium (NDSS), 2005."},{"key":"10.1016\/j.comnet.2007.11.023_bib39","unstructured":"J. Karlin, S. Forrest, J. Rexford, Pretty good BGP (pgBGP), IEEE ICNP, 2006."},{"key":"10.1016\/j.comnet.2007.11.023_bib40","unstructured":"N. Kushman, S. Kandula, D. Katabi, B. Maggs, R-BGP: Staying connected in a connected world, USENIX Symposium on Networked Systems Design and Implementation (NSDI), 2007."},{"issue":"11","key":"10.1016\/j.comnet.2007.11.023_bib41","doi-asserted-by":"crossref","first-page":"770","DOI":"10.1145\/358790.358797","article-title":"Password authentication with insecure communication","volume":"24","author":"Lamport","year":"1981","journal-title":"Communications of the ACM"},{"key":"10.1016\/j.comnet.2007.11.023_bib42","doi-asserted-by":"crossref","unstructured":"Y. Hu, M. Jakobsson, A. Perrig, Efficient constructions for oneway hash chains, in: International Conference on Applied Cryptography and Network Security (ACNS), 2005.","DOI":"10.1007\/11496137_29"},{"key":"10.1016\/j.comnet.2007.11.023_bib43","doi-asserted-by":"crossref","unstructured":"X. Yang, D. Wetherall, T. Anderson, A DoS-limiting network architecture, in: ACM SIGCOMM, 2005.","DOI":"10.1145\/1080091.1080120"},{"key":"10.1016\/j.comnet.2007.11.023_bib44","unstructured":"J. Ioannidis, S. Bellovin, Implementing pushback: router-based defense against DDoS attacks, in: Internet Society Network and Distributed System Security Symposium (NDSS), 2002."},{"key":"10.1016\/j.comnet.2007.11.023_bib45","unstructured":"K. Argyraki, D. Cheriton, Active Internet traffic filtering: realtime response to denial-of-service attacks, in: USENIX Annual Technical Conference (USENIX), 2005."},{"key":"10.1016\/j.comnet.2007.11.023_bib46","doi-asserted-by":"crossref","unstructured":"E. Allman, J. Callas, M. Delany, M. Libbey, J. Fenton, M. Thomas, DomainKeys identified mail (DKIM) signatures, IETF RFC 4871 (Proposed Standard), May 2007.","DOI":"10.17487\/rfc4871"},{"key":"10.1016\/j.comnet.2007.11.023_bib47","unstructured":"Cisco Catalyst Integrated Security \u2013 enabling the self-defending network, Cisco Systems, 2004, White Paper."},{"key":"10.1016\/j.comnet.2007.11.023_bib48","doi-asserted-by":"crossref","unstructured":"H. Lee, M. Kwon, G. Hasker, A. Perrig, BASE: an incrementally deployable mechanism for viable IP spoofing prevention, in: ACM Symposium on Information, Computer and Communication Security (ASIACCS), March 2007.","DOI":"10.1145\/1229285.1229293"}],"container-title":["Computer Networks"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/api.elsevier.com\/content\/article\/PII:S1389128608000492?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/api.elsevier.com\/content\/article\/PII:S1389128608000492?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2020,5,2]],"date-time":"2020-05-02T21:12:10Z","timestamp":1588453930000},"score":1,"resource":{"primary":{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/linkinghub.elsevier.com\/retrieve\/pii\/S1389128608000492"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2008,6]]},"references-count":48,"journal-issue":{"issue":"8","published-print":{"date-parts":[[2008,6]]}},"alternative-id":["S1389128608000492"],"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1016\/j.comnet.2007.11.023","relation":{},"ISSN":["1389-1286"],"issn-type":[{"value":"1389-1286","type":"print"}],"subject":[],"published":{"date-parts":[[2008,6]]}}}