Payload attribution via hierarchical bloom filters

Kulesh Shanmugasundaram, Hervé Brönnimann, Nasir D. Memon · 2004

Payload attribution is an important problem often encountered in network forensics. Given an excerpt of a payload, finding its source and destination is useful for many security applications such as identifying sources and victims of a worm or virus. Although IP traceback techniques have been proposed in the literature, these techniques cannot help when we do not have the entire packet or when we only have an excerpt of the payload.

Read the paper · More papers on PaperTik