PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
November 27, 2002124 citations

Detecting disruptive routers: a distributed network monitoring approach

View Full Paper
KBKatharine A. BradleySCSteven W. CheungNPN. Puketza

Key Points

Key points are not available for this paper at this time.

Abstract

An attractive target for a computer system attacker is the router. An attacker in control of a router can disrupt communication by dropping or misrouting packets passing through the router. We present a protocol called WATCHERS that detects and reacts to routers that drop or misroute packets. WATCHERS is based on the principle of conservation of flow in a network: all data bytes sent into a node, and not destined for that node, are expected to exit the node. WATCHERS tracks this flow, and detects routers that violate the conservation principle. We show that WATCHERS has several advantages over existing network monitoring techniques. We argue that WATCHERS' impact on router performance and WATCHERS' memory requirements are reasonable for many environments. We demonstrate that in ideal conditions WATCHERS makes no false-positive diagnoses. We also describe how WATCHERS can be tuned to perform nearly as well in realistic conditions.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Bradley et al. (2002) studied this question.

synapsesocial.com/papers/6a1bbf8d6f692abb725ed81ehttps://doi.org/10.1109/secpri.1998.674828
Ask AI
Helpful
Bookmark
Share
View Full Paper