{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T04:31:52Z","timestamp":1750307512815,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":51,"publisher":"ACM","license":[{"start":{"date-parts":[[2008,9,22]],"date-time":"2008-09-22T00:00:00Z","timestamp":1222041600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2008,9,22]]},"DOI":"10.1145\/1595676.1595681","type":"proceedings-article","created":{"date-parts":[[2009,8,24]],"date-time":"2009-08-24T14:08:35Z","timestamp":1251122915000},"page":"23-31","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":3,"title":["ROFL"],"prefix":"10.1145","author":[{"given":"Hang","family":"Zhao","sequence":"first","affiliation":[{"name":"Columbia University, New York, NY, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Chi-Kin","family":"Chau","sequence":"additional","affiliation":[{"name":"University of Cambridge, Cambridge, UK"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Steven M.","family":"Bellovin","sequence":"additional","affiliation":[{"name":"Columbia University, New York, NY, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2008,9,22]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"The Design and Analysis of Computer Algorithms","author":"Aho A.V.","year":"1974","unstructured":"A.V. Aho , J.E. Hopcroft , and J.D. Ullman . The Design and Analysis of Computer Algorithms . Addison-Wesley , 1974 . A.V. Aho, J.E. Hopcroft, and J.D. Ullman. The Design and Analysis of Computer Algorithms. Addison-Wesley, 1974."},{"key":"e_1_3_2_1_2_1","volume-title":"Internet Engineering Task Force","author":"Bellovin S.","year":"1994","unstructured":"S. Bellovin . On many addresses per host. RFC 1681 , Internet Engineering Task Force , Aug. 1994 . S. Bellovin. On many addresses per host. RFC 1681, Internet Engineering Task Force, Aug. 1994."},{"key":"e_1_3_2_1_3_1","first-page":"39","volume-title":"Distributed firewalls. ;login","author":"Bellovin S.M.","year":"1999","unstructured":"S.M. Bellovin . Distributed firewalls. ;login :, pages 39 -- 47 , November 1999 . S.M. Bellovin. Distributed firewalls. ;login:, pages 39--47, November 1999."},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSAC.2004.3"},{"key":"e_1_3_2_1_5_1","first-page":"70","volume-title":"Worm propagation strategies in an IPv6 Internet. ;login","author":"Bellovin S.M.","year":"2006","unstructured":"S.M. Bellovin , A. Keromytis , and B. Cheswick . Worm propagation strategies in an IPv6 Internet. ;login :, pages 70 -- 76 , February 2006 . S.M. Bellovin, A. Keromytis, and B. Cheswick. Worm propagation strategies in an IPv6 Internet. ;login:, pages 70--76, February 2006."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/TCOM.1980.1094684"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/996546.996550"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/1282380.1282382"},{"key":"e_1_3_2_1_9_1","volume-title":"Usenix Security","author":"Casado M.","year":"2006","unstructured":"M. Casado , T. Garfinkel , A. Akella , M. Freedman , D. Boneh , N. McKeown , and S. Shenker . Sane: A protection architecture for enterprise networks . In Usenix Security , August 2006 . M. Casado, T. Garfinkel, A. Akella, M. Freedman, D. Boneh, N. McKeown, and S. Shenker. Sane: A protection architecture for enterprise networks. In Usenix Security, August 2006."},{"key":"e_1_3_2_1_10_1","unstructured":"V. Cerf 2004. Private conversation.  V. Cerf 2004. Private conversation."},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/1159913.1159957"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1109\/JSAC.2008.080921"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM.2006.125"},{"key":"e_1_3_2_1_14_1","volume-title":"Firewalls and Internet Security: Repelling the Wily Hacker","author":"Cheswick W.R.","year":"1994","unstructured":"W.R. Cheswick and S.M. Bellovin . Firewalls and Internet Security: Repelling the Wily Hacker . Addison-Wesley , Reading, MA , first edition, 1994 . W.R. Cheswick and S.M. Bellovin. Firewalls and Internet Security: Repelling the Wily Hacker. Addison-Wesley, Reading, MA, first edition, 1994."},{"key":"e_1_3_2_1_15_1","volume-title":"Firewalls and Internet Security","author":"Cheswick W.R.","year":"2003","unstructured":"W.R. Cheswick , S.M. Bellovin , and A.D. Rubin . Firewalls and Internet Security ; Repelling the Wily Hacker. Addison-Wesley , Reading, MA, second edition, 2003 . W.R. Cheswick, S.M. Bellovin, and A.D. Rubin. Firewalls and Internet Security; Repelling the Wily Hacker. Addison-Wesley, Reading, MA, second edition, 2003."},{"key":"e_1_3_2_1_16_1","volume-title":"Cisco Systems","author":"Remotely","year":"2005","unstructured":"Remotely triggered black hole filter -- destination based and source based . Cisco Systems , 2005 . White paper. Remotely triggered black hole filter -- destination based and source based. Cisco Systems, 2005. White paper."},{"key":"e_1_3_2_1_17_1","volume-title":"Internet Engineering Task Force","author":"Coltun R.","year":"1999","unstructured":"R. Coltun , D. Ferguson , and J. Moy . OSPF for IPv6. RFC 2740 , Internet Engineering Task Force , Dec. 1999 . R. Coltun, D. Ferguson, and J. Moy. OSPF for IPv6. RFC 2740, Internet Engineering Task Force, Dec. 1999."},{"key":"e_1_3_2_1_18_1","volume-title":"Internet Engineering Task Force","author":"Deering S.","year":"1998","unstructured":"S. Deering and R. Hinden . Internet protocol, version 6 (IPv6) specification. RFC 2460 , Internet Engineering Task Force , Dec. 1998 . S. Deering and R. Hinden. Internet protocol, version 6 (IPv6) specification. RFC 2460, Internet Engineering Task Force, Dec. 1998."},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1007\/BF01386390"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/116030.116036"},{"key":"e_1_3_2_1_22_1","volume-title":"Internet Engineering Task Force","author":"Fuller V.","year":"2006","unstructured":"V. Fuller and T. Li . Classless inter-domain routing (CIDR). RFC 4632 , Internet Engineering Task Force , Aug. 2006 . V. Fuller and T. Li. Classless inter-domain routing (CIDR). RFC 4632, Internet Engineering Task Force, Aug. 2006."},{"key":"e_1_3_2_1_23_1","volume-title":"Internet Engineering Task Force","author":"Gill V.","year":"2007","unstructured":"V. Gill , J. Heasley , D. Meyer , P. Savola , and C. Pignataro . The generalized ttl security mechanism (GTSM). RFC 5082 , Internet Engineering Task Force , Oct. 2007 . V. Gill, J. Heasley, D. Meyer, P. Savola, and C. Pignataro. The generalized ttl security mechanism (GTSM). RFC 5082, Internet Engineering Task Force, Oct. 2007."},{"key":"e_1_3_2_1_24_1","volume-title":"Proceedings of the Eleventh Usenix Security Symposium","author":"Gleitz P.M.","year":"2001","unstructured":"P.M. Gleitz and S.M. Bellovin . Transient addressing for related processes: Improved firewalling by using IPv6 and multiple addresses per host . In Proceedings of the Eleventh Usenix Security Symposium , August 2001 . P.M. Gleitz and S.M. Bellovin. Transient addressing for related processes: Improved firewalling by using IPv6 and multiple addresses per host. In Proceedings of the Eleventh Usenix Security Symposium, August 2001."},{"key":"e_1_3_2_1_25_1","volume-title":"NANOG","author":"Greene B.R.","year":"2001","unstructured":"B.R. Greene , C.L. Morrow , and B.W. Gemberling . ISP security -- real world techniques: Remote triggered black hole filtering and backscatter traceback . NANOG , October 2001 . B.R. Greene, C.L. Morrow, and B.W. Gemberling. ISP security -- real world techniques: Remote triggered black hole filtering and backscatter traceback. NANOG, October 2001."},{"key":"e_1_3_2_1_26_1","volume-title":"November","author":"Griffin T.G.","year":"2005","unstructured":"T.G. Griffin and G. Huston . RFC 4264: BGP wedgies , November 2005 . T.G. Griffin and G. Huston. RFC 4264: BGP wedgies, November 2005."},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/90.993304"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/1090191.1080094"},{"key":"e_1_3_2_1_29_1","volume-title":"Internet Engineering Task Force","author":"Hain T.","year":"2000","unstructured":"T. Hain . Architectural implications of NAT. RFC 2993 , Internet Engineering Task Force , Nov. 2000 . T. Hain. Architectural implications of NAT. RFC 2993, Internet Engineering Task Force, Nov. 2000."},{"key":"e_1_3_2_1_30_1","volume-title":"Internet Engineering Task Force","author":"Heffernan A.","year":"1998","unstructured":"A. Heffernan . Protection of BGP sessions via the TCP MD5 signature option. RFC 2385 , Internet Engineering Task Force , Aug. 1998 . A. Heffernan. Protection of BGP sessions via the TCP MD5 signature option. RFC 2385, Internet Engineering Task Force, Aug. 1998."},{"key":"e_1_3_2_1_31_1","volume-title":"Internet Engineering Task Force","author":"Holdrege M.","year":"2001","unstructured":"M. Holdrege and P. Srisuresh . Protocol complications with the IP network address translator. RFC 3027 , Internet Engineering Task Force , Jan. 2001 . M. Holdrege and P. Srisuresh. Protocol complications with the IP network address translator. RFC 3027, Internet Engineering Task Force, Jan. 2001."},{"key":"e_1_3_2_1_32_1","volume-title":"Proc. Internet Society Symposium on Network and Distributed System Security","author":"Ioannidis J.","year":"2002","unstructured":"J. Ioannidis and S.M. Bellovin . Implementing pushback: Router-based defense against DDoS attacks . In Proc. Internet Society Symposium on Network and Distributed System Security , 2002 . J. Ioannidis and S.M. Bellovin. Implementing pushback: Router-based defense against DDoS attacks. In Proc. Internet Society Symposium on Network and Distributed System Security, 2002."},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1145\/321992.321993"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.5555\/1267591.1267593"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1109\/49.839934"},{"key":"e_1_3_2_1_36_1","volume-title":"Internet Engineering Task Force","author":"Kent S.","year":"2005","unstructured":"S. Kent and K. Seo . Security architecture for the Internet Protocol. RFC 4301 , Internet Engineering Task Force , Dec. 2005 . S. Kent and K. Seo. Security architecture for the Internet Protocol. RFC 4301, Internet Engineering Task Force, Dec. 2005."},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/571697.571724"},{"key":"e_1_3_2_1_38_1","volume-title":"Dissemination of flow specification rules. Internet draft","author":"Marques P.","year":"2008","unstructured":"P. Marques , N. Sheth , R. Raszuk , B. Greene , J. Mauch , and D. McPherson . Dissemination of flow specification rules. Internet draft ; work in progress, April 2008 . (draft-ietf-idr-flow-spec-01.txt). P. Marques, N. Sheth, R. Raszuk, B. Greene, J. Mauch, and D. McPherson. Dissemination of flow specification rules. Internet draft; work in progress, April 2008. (draft-ietf-idr-flow-spec-01.txt)."},{"key":"e_1_3_2_1_39_1","volume-title":"August","author":"McPherson D.","year":"2002","unstructured":"D. McPherson , V. Gill , D. Walton , and A. Retana . RFC 3345: Border Gateway Protocol (BGP) persistent route oscillation condition , August 2002 . D. McPherson, V. Gill, D. Walton, and A. Retana. RFC 3345: Border Gateway Protocol (BGP) persistent route oscillation condition, August 2002."},{"key":"e_1_3_2_1_41_1","volume-title":"Internet Engineering Task Force","author":"Moy J.","year":"1998","unstructured":"J. Moy . OSPF version 2. RFC 2328 , Internet Engineering Task Force , Apr. 1998 . J. Moy. OSPF version 2. RFC 2328, Internet Engineering Task Force, Apr. 1998."},{"key":"e_1_3_2_1_42_1","volume-title":"Internet Engineering Task Force","author":"Murphy S.","year":"1997","unstructured":"S. Murphy , M. Badger , and B. Wellington . OSPF with digital signatures. RFC 2154 , Internet Engineering Task Force , June 1997 . S. Murphy, M. Badger, and B. Wellington. OSPF with digital signatures. RFC 2154, Internet Engineering Task Force, June 1997."},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/1013879.802675"},{"key":"e_1_3_2_1_45_1","volume-title":"Internet Engineering Task Force","author":"Postel J.","year":"1980","unstructured":"J. Postel . User datagram protocol. RFC 768 , Internet Engineering Task Force , Aug. 1980 . J. Postel. User datagram protocol. RFC 768, Internet Engineering Task Force, Aug. 1980."},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.17487\/rfc0793"},{"key":"e_1_3_2_1_47_1","volume-title":"Internet Engineering Task Force","author":"Rekhter Y.","year":"2006","unstructured":"Y. Rekhter , T. Li , and S. Hares . A border gateway protocol 4 (BGP-4). RFC 4271 , Internet Engineering Task Force , Jan. 2006 . Y. Rekhter, T. Li, and S. Hares. A border gateway protocol 4 (BGP-4). RFC 4271, Internet Engineering Task Force, Jan. 2006."},{"key":"e_1_3_2_1_48_1","volume-title":"NANOG","author":"Rexford J.","year":"2001","unstructured":"J. Rexford , S. Bellovin , and R. Bush . Some initial measurements of prefix length phyltreing . NANOG , May 2001 . J. Rexford, S. Bellovin, and R. Bush. Some initial measurements of prefix length phyltreing. NANOG, May 2001."},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1145\/505202.505218"},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1109\/TNET.2005.857111"},{"key":"e_1_3_2_1_51_1","volume-title":"Internet Engineering Task Force","author":"Srisuresh P.","year":"2001","unstructured":"P. Srisuresh and K. Egevang . Traditional IP network address translator (traditional NAT). RFC 3022 , Internet Engineering Task Force , Jan. 2001 . P. Srisuresh and K. Egevang. Traditional IP network address translator (traditional NAT). RFC 3022, Internet Engineering Task Force, Jan. 2001."},{"key":"e_1_3_2_1_52_1","volume-title":"Internet Engineering Task Force","author":"Steenstrup M.","year":"1993","unstructured":"M. Steenstrup . An architecture for Inter-Domain policy routing. RFC 1478 , Internet Engineering Task Force , June 1993 . M. Steenstrup. An architecture for Inter-Domain policy routing. RFC 1478, Internet Engineering Task Force, June 1993."},{"key":"e_1_3_2_1_53_1","first-page":"12","article-title":"1","volume":"01","year":"2001","unstructured":"WANIPConnection : 1 . Service Template Version 1 . 01 , UPnP Forum, 12 November 2001 . Standardized DCP. WANIPConnection:1. Service Template Version 1.01, UPnP Forum, 12 November 2001. Standardized DCP.","journal-title":"Service Template Version 1"},{"key":"e_1_3_2_1_55_1","volume-title":"Internet transport protocols. XSIS 028112","author":"Integration Standard Xerox System","year":"1981","unstructured":"Xerox System Integration Standard . Internet transport protocols. XSIS 028112 , Xerox Corporation , December 1981 . Xerox System Integration Standard. Internet transport protocols. XSIS 028112, Xerox Corporation, December 1981."}],"event":{"name":"NSPW '08: 2008 New Security Paradigms Workshop","sponsor":["ACM Association for Computing Machinery"],"location":"Lake Tahoe California USA","acronym":"NSPW '08"},"container-title":["Proceedings of the 2008 New Security Paradigms Workshop"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1595676.1595681","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1595676.1595681","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T12:18:03Z","timestamp":1750249083000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1595676.1595681"}},"subtitle":["routing as the firewall layer"],"short-title":[],"issued":{"date-parts":[[2008,9,22]]},"references-count":51,"alternative-id":["10.1145\/1595676.1595681","10.1145\/1595676"],"URL":"https:\/\/doi.org\/10.1145\/1595676.1595681","relation":{},"subject":[],"published":{"date-parts":[[2008,9,22]]},"assertion":[{"value":"2008-09-22","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}