{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,16]],"date-time":"2025-12-16T12:16:35Z","timestamp":1765887395082,"version":"3.41.0"},"reference-count":25,"publisher":"Association for Computing Machinery (ACM)","issue":"2","license":[{"start":{"date-parts":[[2012,3,29]],"date-time":"2012-03-29T00:00:00Z","timestamp":1332979200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["SIGCOMM Comput. Commun. Rev."],"published-print":{"date-parts":[[2012,3,29]]},"abstract":"<jats:p>There are many deployed approaches for blocking unwanted traffic, either once it reaches the recipient's network, or closer to its point of origin. One of these schemes is based on the notion of traffic carrying capabilities that grant access to a network and\/or end host. However, leveraging capabilities results in added complexity and additional steps in the communication process: Before communication starts a remote host must be vetted and given a capability to use in the subsequent communication. In this paper, we propose a lightweight mechanism that turns the answers provided by DNS name resolution - which Internet communication broadly depends on anyway - into capabilities. While not achieving an ideal capability system, we show the mechanism can be built from commodity technology and is therefore a pragmatic way to gain some of the key benefits of capabilities without requiring new infrastructure.<\/jats:p>","DOI":"10.1145\/2185376.2185386","type":"journal-article","created":{"date-parts":[[2012,4,17]],"date-time":"2012-04-17T12:53:13Z","timestamp":1334667193000},"page":"72-79","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":17,"title":["On building inexpensive network capabilities"],"prefix":"10.1145","volume":"42","author":[{"given":"Craig A.","family":"Shue","sequence":"first","affiliation":[{"name":"Worcester Polytechnic Institute, Worcester, Massachusetts, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Andrew J.","family":"Kalafut","sequence":"additional","affiliation":[{"name":"Grand Valley State University, Allendale, Michigan, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mark","family":"Allman","sequence":"additional","affiliation":[{"name":"International Computer Science Institute, Berkeley, California, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Curtis R.","family":"Taylor","sequence":"additional","affiliation":[{"name":"Oak Ridge National Laboratory, Oak Ridge, Tennessee, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2012,3,29]]},"reference":[{"key":"e_1_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/972374.972382"},{"key":"e_1_2_1_2_1","volume-title":"DNS Security Introduction and Requirements. RFC","author":"Arends R.","year":"2005","unstructured":"R. Arends , R. Austein , M. Larson , D. Massey , and S. Rose . DNS Security Introduction and Requirements. RFC 4033, Mar. 2005 . R. Arends, R. Austein, M. Larson, D. Massey, and S. Rose. DNS Security Introduction and Requirements. RFC 4033, Mar. 2005."},{"key":"e_1_2_1_3_1","volume-title":"Fourth Workshop on Hot Topics in Networks","author":"Argyraki K.","year":"2005","unstructured":"K. Argyraki and D. Cheriton . Network Capabilities: The Good, the Bad and the Ugly . In Fourth Workshop on Hot Topics in Networks , Nov. 2005 . K. Argyraki and D. Cheriton. Network Capabilities: The Good, the Bad and the Ugly. In Fourth Workshop on Hot Topics in Networks, Nov. 2005."},{"key":"e_1_2_1_4_1","volume-title":"Off By Default. In ACM Workshop on Hot Topics in Networks","author":"Ballani H.","year":"2005","unstructured":"H. Ballani , Y. Chawathe , S. Ratnasamy , T. Roscoe , and S. Shenker . Off By Default. In ACM Workshop on Hot Topics in Networks , 2005 . H. Ballani, Y. Chawathe, S. Ratnasamy, T. Roscoe, and S. Shenker. Off By Default. In ACM Workshop on Hot Topics in Networks, 2005."},{"key":"e_1_2_1_5_1","volume-title":"Reducing DNS Caching. In Global Internet Symposium","author":"Bhatti S.","year":"2011","unstructured":"S. Bhatti and R. Atkinson . Reducing DNS Caching. In Global Internet Symposium , Apr. 2011 . S. Bhatti and R. Atkinson. Reducing DNS Caching. In Global Internet Symposium, Apr. 2011."},{"key":"e_1_2_1_6_1","volume-title":"IETF Draft","author":"Contavalli C.","year":"2011","unstructured":"C. Contavalli , W. van der Gaast, S. Leach, and D. Rodden. Client subnet in DNS requests . IETF Draft , January 2011 . C. Contavalli, W. van der Gaast, S. Leach, and D. Rodden. Client subnet in DNS requests. IETF Draft, January 2011."},{"key":"e_1_2_1_7_1","volume-title":"DNS Request and Transaction Signatures (SIG(0)s). RFC","author":"Eastlake D.","year":"2000","unstructured":"D. Eastlake . DNS Request and Transaction Signatures (SIG(0)s). RFC 2931, Sept. 2000 . D. Eastlake. DNS Request and Transaction Signatures (SIG(0)s). RFC 2931, Sept. 2000."},{"volume-title":"July","year":"2011","key":"e_1_2_1_8_1","unstructured":"Google. Google Public DNS , July 2011 . http:\/\/code.google.com\/speed\/public-dns\/. Google. Google Public DNS, July 2011. http:\/\/code.google.com\/speed\/public-dns\/."},{"key":"e_1_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/1462148.1462150"},{"key":"e_1_2_1_10_1","volume-title":"Fast Portscan Detection Using Sequential Hypothesis Testing. In IEEE Symposium on Security and Privacy","author":"Jung J.","year":"2004","unstructured":"J. Jung , V. Paxson , A. W. Berger , and H. Balakrishnan . Fast Portscan Detection Using Sequential Hypothesis Testing. In IEEE Symposium on Security and Privacy , 2004 . J. Jung, V. Paxson, A. W. Berger, and H. Balakrishnan. Fast Portscan Detection Using Sequential Hypothesis Testing. In IEEE Symposium on Security and Privacy, 2004."},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/972374.972383"},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/1402958.1402981"},{"key":"e_1_2_1_13_1","volume-title":"USENIX","author":"Mao Z. M.","year":"2002","unstructured":"Z. M. Mao , C. D. Cranor , F. Douglis , M. Rabinovich , O. Spatscheck , and J. Wang . A precise and efficient evaluation of the proximity between web clients and their local DNS servers . In USENIX , 2002 . Z. M. Mao, C. D. Cranor, F. Douglis, M. Rabinovich, O. Spatscheck, and J. Wang. A precise and efficient evaluation of the proximity between web clients and their local DNS servers. In USENIX, 2002."},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/1868447.1868456"},{"key":"e_1_2_1_15_1","volume-title":"Oct.","author":"DNS.","year":"2011","unstructured":"Open DNS. How it works - a faster Internet , Oct. 2011 . http:\/\/www.afasterinternet.com\/howitworks.htm. OpenDNS. How it works - a faster Internet, Oct. 2011. http:\/\/www.afasterinternet.com\/howitworks.htm."},{"key":"e_1_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/1028788.1028792"},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/1282380.1282413"},{"key":"e_1_2_1_18_1","unstructured":"C. Project. Dns prefetching. http:\/\/www.chromium.org\/developers\/design-documents\/dns-prefetching.  C. Project. Dns prefetching. http:\/\/www.chromium.org\/developers\/design-documents\/dns-prefetching."},{"key":"e_1_2_1_19_1","volume-title":"Evasive Internet: Reducing Internet Vulnerability Through Transient Addressing. In IEEE Global Internet Symposium","author":"Rabinovich M.","year":"2010","unstructured":"M. Rabinovich and O. Spatscheck . Evasive Internet: Reducing Internet Vulnerability Through Transient Addressing. In IEEE Global Internet Symposium , 2010 . M. Rabinovich and O. Spatscheck. Evasive Internet: Reducing Internet Vulnerability Through Transient Addressing. In IEEE Global Internet Symposium, 2010."},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/1015467.1015487"},{"key":"e_1_2_1_21_1","volume-title":"July","author":"Project The Honeynet","year":"2007","unstructured":"The Honeynet Project . Know your enemy: Fast-flux service networks , July 2007 . http:\/\/www.honeynet.org\/papers\/ff. The Honeynet Project. Know your enemy: Fast-flux service networks, July 2007. http:\/\/www.honeynet.org\/papers\/ff."},{"volume-title":"July","year":"2011","key":"e_1_2_1_22_1","unstructured":"w3schools.com. Browser statistics , July 2011 . http:\/\/ www.w3schools.com\/browsers\/browsers_stats.asp. w3schools.com. Browser statistics, July 2011. http:\/\/ www.w3schools.com\/browsers\/browsers_stats.asp."},{"key":"e_1_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/SECPRI.2004.1301320"},{"key":"e_1_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/JSAC.2006.877138"},{"key":"e_1_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/TNET.2007.914506"}],"container-title":["ACM SIGCOMM Computer Communication Review"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2185376.2185386","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2185376.2185386","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T10:06:01Z","timestamp":1750241161000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2185376.2185386"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2012,3,29]]},"references-count":25,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2012,3,29]]}},"alternative-id":["10.1145\/2185376.2185386"],"URL":"https:\/\/doi.org\/10.1145\/2185376.2185386","relation":{},"ISSN":["0146-4833"],"issn-type":[{"type":"print","value":"0146-4833"}],"subject":[],"published":{"date-parts":[[2012,3,29]]},"assertion":[{"value":"2012-03-29","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}