<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=us-ascii">
<meta name=Generator content="Microsoft Word 12 (filtered medium)">
<style>
<!--
/* Font Definitions */
@font-face
        {font-family:Wingdings;
        panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:Consolas;
        panose-1:2 11 6 9 2 2 4 3 2 4;}
@font-face
        {font-family:"Lucida Grande";
        panose-1:0 0 0 0 0 0 0 0 0 0;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri","sans-serif";}
h3
        {mso-style-priority:9;
        mso-style-link:"Heading 3 Char";
        mso-margin-top-alt:auto;
        margin-right:0in;
        mso-margin-bottom-alt:auto;
        margin-left:0in;
        font-size:13.5pt;
        font-family:"Times New Roman","serif";
        font-weight:bold;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
p.MsoPlainText, li.MsoPlainText, div.MsoPlainText
        {mso-style-priority:99;
        mso-style-link:"Plain Text Char";
        margin:0in;
        margin-bottom:.0001pt;
        font-size:10.5pt;
        font-family:Consolas;}
p
        {mso-style-priority:99;
        mso-margin-top-alt:auto;
        margin-right:0in;
        mso-margin-bottom-alt:auto;
        margin-left:0in;
        font-size:12.0pt;
        font-family:"Times New Roman","serif";}
span.PlainTextChar
        {mso-style-name:"Plain Text Char";
        mso-style-priority:99;
        mso-style-link:"Plain Text";
        font-family:Consolas;}
span.Heading3Char
        {mso-style-name:"Heading 3 Char";
        mso-style-priority:9;
        mso-style-link:"Heading 3";
        font-family:"Times New Roman","serif";
        font-weight:bold;}
span.apple-style-span
        {mso-style-name:apple-style-span;}
span.apple-converted-space
        {mso-style-name:apple-converted-space;}
span.twikinewlink
        {mso-style-name:twikinewlink;}
.MsoChpDefault
        {mso-style-type:export-only;}
@page Section1
        {size:8.5in 11.0in;
        margin:1.0in 92.4pt 1.0in 92.4pt;}
div.Section1
        {page:Section1;}
/* List Definitions */
@list l0
        {mso-list-id:435752261;
        mso-list-template-ids:-1837355078;}
@list l0:level1
        {mso-level-number-format:bullet;
        mso-level-text:\F0B7;
        mso-level-tab-stop:.5in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Symbol;}
@list l0:level2
        {mso-level-number-format:bullet;
        mso-level-text:o;
        mso-level-tab-stop:1.0in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:"Courier New";
        mso-bidi-font-family:"Times New Roman";}
@list l1
        {mso-list-id:1032536462;
        mso-list-template-ids:1748781268;}
@list l1:level1
        {mso-level-number-format:bullet;
        mso-level-text:\F0B7;
        mso-level-tab-stop:.5in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Symbol;}
ol
        {margin-bottom:0in;}
ul
        {margin-bottom:0in;}
-->
</style>
<!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang=EN-US link=blue vlink=purple>
<div class=Section1>
<p class=MsoPlainText>The following is from someone else’s notes on a talk
given at SIGCOMM08.<o:p></o:p></p>
<p class=MsoPlainText><o:p> </o:p></p>
<div style='mso-element:para-border-div;border:solid #E9E4D2 1.0pt;padding:
1.0pt 4.0pt 1.0pt 4.0pt'>
<h3 style='mso-margin-top-alt:12.0pt;margin-right:0in;margin-bottom:4.2pt;
margin-left:0in;line-height:103%;border:none;padding:0in'><span
style='font-family:"Lucida Grande","serif";color:#AA0000'>To Filter or to
Authorize: Network-Layer<span class=apple-converted-space> </span><span
class=twikinewlink><span style='border:solid #CCCCCC 1.0pt;padding:0in'>DoS</span></span><span
class=apple-converted-space> </span>Defense Against Multimillion-node
Botnets<o:p></o:p></span></h3>
</div>
<p style='mso-margin-top-alt:12.0pt;margin-right:0in;margin-bottom:0in;
margin-left:0in;margin-bottom:.0001pt;line-height:13.5pt'><strong><span
style='font-size:10.0pt;font-family:"Lucida Grande","serif";color:black'>Xin
Liu</span></strong><span class=apple-converted-space><span style='font-size:
10.0pt;font-family:"Lucida Grande","serif";color:black'> </span></span><span
style='font-size:10.0pt;font-family:"Lucida Grande","serif";color:black'>(UC
Irvine); Xiaowei Yang (UC Irvine); Yanbin Lu (UC Irvine)<o:p></o:p></span></p>
<p style='mso-margin-top-alt:12.0pt;margin-right:0in;margin-bottom:0in;
margin-left:0in;margin-bottom:.0001pt;line-height:13.5pt'><span
style='font-size:10.0pt;font-family:"Lucida Grande","serif";color:black'>Which
approach works better against flooding DOS attacks from Botnets?<o:p></o:p></span></p>
<ul type=disc>
<li class=MsoNormal style='color:black;mso-margin-top-alt:auto;mso-margin-bottom-alt:
auto;line-height:16.8pt;mso-list:l0 level1 lfo1'><span style='font-size:
10.0pt;font-family:"Lucida Grande","serif"'>filtering-based approaches<o:p></o:p></span></li>
<ul type=circle>
<li class=MsoNormal style='color:black;mso-margin-top-alt:auto;mso-margin-bottom-alt:
auto;line-height:16.8pt;mso-list:l0 level2 lfo1'><span style='font-size:
10.0pt;font-family:"Lucida Grande","serif"'>receiver asks network to
install filters blocking specific traffic<o:p></o:p></span></li>
</ul>
<li class=MsoNormal style='color:black;mso-margin-top-alt:auto;mso-margin-bottom-alt:
auto;line-height:16.8pt;mso-list:l0 level1 lfo1'><span style='font-size:
10.0pt;font-family:"Lucida Grande","serif"'>authorization-based approaches
(capabilities)<o:p></o:p></span></li>
<ul type=circle>
<li class=MsoNormal style='color:black;mso-margin-top-alt:auto;mso-margin-bottom-alt:
auto;line-height:16.8pt;mso-list:l0 level2 lfo1'><span style='font-size:
10.0pt;font-family:"Lucida Grande","serif"'>source requests permission to
send, marks traffic with indication of permission (securely, to some
extent)<o:p></o:p></span></li>
</ul>
</ul>
<p class=MsoNormal style='line-height:13.5pt'><span class=apple-style-span><span
style='font-size:10.0pt;font-family:"Lucida Grande","serif";color:black'>Ongoing
controversy over which approach works best</span><o:p></o:p></span></p>
<p style='mso-margin-top-alt:12.0pt;margin-right:0in;margin-bottom:0in;
margin-left:0in;margin-bottom:.0001pt;line-height:13.5pt'><span
style='font-size:10.0pt;font-family:"Lucida Grande","serif";color:black'>Compared
approaches under various attacks</span><o:p></o:p></p>
<ul type=disc>
<li class=MsoNormal style='color:black;mso-margin-top-alt:auto;mso-margin-bottom-alt:
auto;line-height:16.8pt;mso-list:l1 level1 lfo2'><span style='font-size:
10.0pt;font-family:"Lucida Grande","serif"'>tried to design better
filter-based system, StopIt, to make comparison useful/fair<o:p></o:p></span></li>
</ul>
<p style='mso-margin-top-alt:12.0pt;margin-right:0in;margin-bottom:0in;
margin-left:0in;margin-bottom:.0001pt;line-height:13.5pt'><span
style='font-size:10.0pt;font-family:"Lucida Grande","serif";color:black'>From
their abstract:<span class=apple-converted-space><i> </i></span><i>Our
results show that StopIt outperforms existing filter-based systems, and can
prevent legitimate communications from being disrupted by various<span
class=apple-converted-space> </span><span class=twikinewlink><span
style='border:solid #CCCCCC 1.0pt;padding:0in'>DoS</span></span><span
class=apple-converted-space> </span>flooding attacks. It also outperforms
capability-based systems in most attack scenarios, but a capability-based
system is more effective in a type of attack that the attack traffic does not
reach a victim, but congests a link shared by the victim. These results suggest
that both filters and capabilities are highly effective<span
class=apple-converted-space> </span><span class=twikinewlink><span
style='border:solid #CCCCCC 1.0pt;padding:0in'>DoS</span></span><span
class=apple-converted-space> </span>defense mechanisms, but neither is
more effective than the other in all types of<span class=apple-converted-space> </span><span
class=twikinewlink><span style='border:solid #CCCCCC 1.0pt;padding:0in'>DoS</span></span><span
class=apple-converted-space> </span>attacks.</i><o:p></o:p></span></p>
<p class=MsoPlainText><o:p> </o:p></p>
<p class=MsoPlainText><o:p> </o:p></p>
<p class=MsoPlainText>________________________<o:p></o:p></p>
<p class=MsoPlainText>Alan Karp<o:p></o:p></p>
<p class=MsoPlainText>Principal Scientist<o:p></o:p></p>
<p class=MsoPlainText>Virus Safe Computing Initiative<o:p></o:p></p>
<p class=MsoPlainText>Hewlett-Packard Laboratories<o:p></o:p></p>
<p class=MsoPlainText>1501 Page Mill Road<o:p></o:p></p>
<p class=MsoPlainText>Palo Alto, CA 94304<o:p></o:p></p>
<p class=MsoPlainText>(650) 857-3967, fax (650) 857-7029<o:p></o:p></p>
<p class=MsoPlainText>http://www.hpl.hp.com/personal/Alan_Karp<o:p></o:p></p>
<p class=MsoPlainText><o:p> </o:p></p>
<p class=MsoPlainText><o:p> </o:p></p>
</div>
</body>
</html>