{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,15]],"date-time":"2026-01-15T09:08:47Z","timestamp":1768468127623,"version":"3.49.0"},"reference-count":71,"publisher":"Association for Computing Machinery (ACM)","issue":"2","license":[{"start":{"date-parts":[[2012,7,1]],"date-time":"2012-07-01T00:00:00Z","timestamp":1341100800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100003977","name":"Israel Science Foundation","doi-asserted-by":"publisher","award":["206703"],"award-info":[{"award-number":["206703"]}],"id":[{"id":"10.13039\/501100003977","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Inf. Syst. Secur."],"published-print":{"date-parts":[[2012,7]]},"abstract":"<jats:p>We present LOT, a lightweight plug and play secure tunneling protocol deployed at network gateways. Two communicating gateways, A and B, running LOT would automatically detect each other and establish an efficient tunnel, securing communication between them. LOT tunnels allow A to discard spoofed packets that specify source addresses in B\u2019s network and vice versa. This helps to mitigate many attacks, including DNS poisoning, network scans, and most notably (Distributed) Denial of Service (DoS).<\/jats:p>\n          <jats:p>LOT tunnels provide several additional defenses against DoS attacks. Specifically, since packets received from LOT-protected networks cannot be spoofed, LOT gateways implement quotas, identifying and blocking packet floods from specific networks. Furthermore, a receiving LOT gateway (e.g., B) can send the quota assigned to each tunnel to the peer gateway (A), which can then enforce near-source quotas, reducing waste and congestion by filtering excessive traffic before it leaves the source network. Similarly, LOT tunnels facilitate near-source filtering, where the sending gateway discards packets based on filtering rules defined by the destination gateway. LOT gateways also implement an intergateway congestion detection mechanism, allowing sending gateways to detect when their packets get dropped before reaching the destination gateway and to perform appropriate near-source filtering to block the congesting traffic; this helps against DoS attacks on the backbone connecting the two gateways.<\/jats:p>\n          <jats:p>LOT is practical: it is easy to manage (plug and play, requires no coordination between gateways), deployed incrementally at edge gateways (not at hosts and core routers), and has negligible overhead in terms of bandwidth and processing, as we validate experimentally. LOT storage requirements are also modest.<\/jats:p>","DOI":"10.1145\/2240276.2240277","type":"journal-article","created":{"date-parts":[[2012,8,1]],"date-time":"2012-08-01T17:35:16Z","timestamp":1343842516000},"page":"1-30","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":19,"title":["LOT"],"prefix":"10.1145","volume":"15","author":[{"given":"Yossi","family":"Gilad","sequence":"first","affiliation":[{"name":"Bar-Ilan University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Amir","family":"Herzberg","sequence":"additional","affiliation":[{"name":"Bar-Ilan University"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2012,7]]},"reference":[{"key":"e_1_2_1_1_1","unstructured":"Advanced Network Architecture Group. 2011. ANA Spoofer Project. http:\/\/spoofer.csail.mit.edu\/index.php.  Advanced Network Architecture Group. 2011. ANA Spoofer Project. http:\/\/spoofer.csail.mit.edu\/index.php."},{"key":"e_1_2_1_2_1","unstructured":"Aharoni M. and Hidalgo W. M. 2005. Cisco SNMP configuration attack with a GRE tunnel. In Security Focus. http:\/\/www.securityfocus.com\/infocus\/1847.  Aharoni M. and Hidalgo W. M. 2005. Cisco SNMP configuration attack with a GRE tunnel. In Security Focus . http:\/\/www.securityfocus.com\/infocus\/1847."},{"key":"e_1_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/948109.948133"},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/972374.972382"},{"key":"e_1_2_1_5_1","volume-title":"Proceedings of the USENIX Annual Technical Conference, General Track. 135--148","author":"Argyraki K."},{"key":"e_1_2_1_6_1","volume-title":"Proceedings of the 4th Workshop on Hot Topics in Networks.","author":"Argyraki K."},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2007.70209"},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/SRDS.2008.27"},{"key":"e_1_2_1_9_1","doi-asserted-by":"crossref","unstructured":"Baker F. and Savola P. 2004. Ingress filtering for multihomed networks. RFC 3704 (Best Current Practice). The Internet Society.   Baker F. and Savola P. 2004. Ingress filtering for multihomed networks. RFC 3704 (Best Current Practice). The Internet Society.","DOI":"10.17487\/rfc3704"},{"key":"e_1_2_1_10_1","unstructured":"Bellovin S. 2003. ICMP traceback messages. http:\/\/tools.ietf.org\/html\/draft-ietf-itrace-04.  Bellovin S. 2003. ICMP traceback messages. http:\/\/tools.ietf.org\/html\/draft-ietf-itrace-04."},{"key":"e_1_2_1_11_1","unstructured":"Bernstein D. 1996. TCP SYN cookies. http:\/\/cr.yp.to\/syncookies.html.  Bernstein D. 1996. TCP SYN cookies. http:\/\/cr.yp.to\/syncookies.html."},{"key":"e_1_2_1_12_1","volume-title":"Proceedings of Steps to Reducing Unwanted Traffic on the Internet Workshop (SRUTI).","author":"Beverly R."},{"key":"e_1_2_1_13_1","volume-title":"Proceedings of the Annual Joint Conference of the IEEE Computer and Communications Societies (INFOCOM). 536--547","author":"Bremler-Barr A."},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1109\/MCOM.2002.1039856"},{"key":"e_1_2_1_15_1","unstructured":"Cisco Systems. 2007. Pre-Fragmentation for IPsec VPNs. http:\/\/www.ciscosystems.cd\/en\/US\/docs\/ios\/sec_secure_connectivity\/configuration\/guide\/sec_pre_frag_vpns.pdf.  Cisco Systems. 2007. Pre-Fragmentation for IPsec VPNs. http:\/\/www.ciscosystems.cd\/en\/US\/docs\/ios\/sec_secure_connectivity\/configuration\/guide\/sec_pre_frag_vpns.pdf."},{"key":"e_1_2_1_16_1","doi-asserted-by":"crossref","unstructured":"Daemen J. and Rijmen V. 2002. The Design of Rijndael: AES--the Advanced Encryption Standard. Springer Verlag.   Daemen J. and Rijmen V. 2002. The Design of Rijndael: AES--the Advanced Encryption Standard. Springer Verlag.","DOI":"10.1007\/978-3-662-04722-4_1"},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/505586.505588"},{"key":"e_1_2_1_18_1","doi-asserted-by":"crossref","unstructured":"Dommety G. 2000. Key and sequence number extensions to GRE. RFC 2890 (Proposed Standard). The Internet Society.   Dommety G. 2000. Key and sequence number extensions to GRE. RFC 2890 (Proposed Standard). The Internet Society.","DOI":"10.17487\/rfc2890"},{"key":"e_1_2_1_19_1","doi-asserted-by":"crossref","unstructured":"Eddy W. 2007. TCP SYN flooding attacks and common mitigations. RFC 4987 (Informational). The Internet Society.  Eddy W. 2007. TCP SYN flooding attacks and common mitigations. RFC 4987 (Informational). The Internet Society.","DOI":"10.17487\/rfc4987"},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-16161-2_13"},{"key":"e_1_2_1_21_1","doi-asserted-by":"crossref","unstructured":"Farinacci D. Li T. Hanks S. Meyer D. and Traina P. 2000. Generic routing encapsulation (GRE). RFC 2784 (Proposed Standard). Updated by RFC 2890. The Internet Society.   Farinacci D. Li T. Hanks S. Meyer D. and Traina P. 2000. Generic routing encapsulation (GRE). RFC 2784 (Proposed Standard). Updated by RFC 2890. The Internet Society.","DOI":"10.17487\/rfc2784"},{"key":"e_1_2_1_22_1","doi-asserted-by":"crossref","unstructured":"Ferguson P. and Senie D. 2000. Network ingress filtering: Defeating denial of service attacks which employ IP Source Address Spoofing. RFC 2827 (Best Current Practice 38). Updated by RFC 3704. The Internet Society.   Ferguson P. and Senie D. 2000. Network ingress filtering: Defeating denial of service attacks which employ IP Source Address Spoofing. RFC 2827 (Best Current Practice 38). Updated by RFC 3704. The Internet Society.","DOI":"10.17487\/rfc2827"},{"key":"e_1_2_1_23_1","volume-title":"Proceedings of the European Symposium on Research in Computer Security (ESORICS). 104--119","author":"Gilad Y."},{"key":"e_1_2_1_24_1","volume-title":"Proceedings of the USENIX Workshop on Offensive Technologies.","author":"Gilad Y."},{"key":"e_1_2_1_25_1","unstructured":"Gilad Y. and Herzberg A. 2011b. Lightweight opportunistic tunneling. Tech. rep. http:\/\/u.cs.biu.ac.il\/~herzbea\/security\/TR\/11_02.pdf.  Gilad Y. and Herzberg A. 2011b. Lightweight opportunistic tunneling. Tech. rep. http:\/\/u.cs.biu.ac.il\/~herzbea\/security\/TR\/11_02.pdf."},{"key":"e_1_2_1_26_1","unstructured":"Gilmore J. 2003. FreeS\/WAN Project. www.freeswan.org.  Gilmore J. 2003. FreeS\/WAN Project. www.freeswan.org."},{"key":"e_1_2_1_27_1","volume-title":"Basic Tools","author":"Goldreich O."},{"key":"e_1_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1016\/S0140-3664(99)00064-X"},{"key":"e_1_2_1_29_1","doi-asserted-by":"crossref","unstructured":"Heffernan A. 1998. Protection of BGP Sessions via the TCP MD5 Signature Option. RFC 2385 (Proposed Standard). The Internet Society.   Heffernan A. 1998. Protection of BGP Sessions via the TCP MD5 Signature Option. RFC 2385 (Proposed Standard). The Internet Society.","DOI":"10.17487\/rfc2385"},{"key":"e_1_2_1_30_1","doi-asserted-by":"crossref","unstructured":"Heffner J. Mathis M. and Chandler B. 2007. IPv4 reassembly errors at high data rates. RFC 4963 (Informational). The Internet Society.  Heffner J. Mathis M. and Chandler B. 2007. IPv4 reassembly errors at high data rates. RFC 4963 (Informational). The Internet Society.","DOI":"10.17487\/rfc4963"},{"key":"e_1_2_1_31_1","doi-asserted-by":"crossref","unstructured":"Hoffman P. 2005. Cryptographic suites for IPsec. RFC 4308 (Proposed Standard). The Internet Society.  Hoffman P. 2005. Cryptographic suites for IPsec. RFC 4308 (Proposed Standard). The Internet Society.","DOI":"10.17487\/rfc4308"},{"key":"e_1_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/1232919.1232924"},{"key":"e_1_2_1_33_1","unstructured":"IANA. 2002. Special-use IPv4 addresses. RFC 3330 (Informational). The Internet Society.   IANA. 2002. Special-use IPv4 addresses. RFC 3330 (Informational). The Internet Society."},{"key":"e_1_2_1_34_1","volume-title":"Implementing Pushback: Router-based defense against DDoS attacks","author":"Ioannidis J.","year":"2002"},{"key":"e_1_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2002.1012421"},{"key":"e_1_2_1_36_1","volume-title":"Proceedings of the Black Hat Conference. http:\/\/www.doxpara.com\/DMK_BO2K8.ppt.","author":"Kaminsky D.","year":"2008"},{"key":"e_1_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICNP.2006.320179"},{"key":"e_1_2_1_38_1","doi-asserted-by":"crossref","unstructured":"Kaufman C. 2005. Internet key exchange (IKEv2) protocol. RFC 4306 (Proposed Standard). Updated by RFC 5282. The Internet Society.  Kaufman C. 2005. Internet key exchange (IKEv2) protocol. RFC 4306 (Proposed Standard). Updated by RFC 5282. The Internet Society.","DOI":"10.17487\/rfc4306"},{"key":"e_1_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/948109.948113"},{"key":"e_1_2_1_40_1","doi-asserted-by":"crossref","unstructured":"Kent C. A. and Mogul J. C. 1987. Fragmentation Considered Harmful. Res. rep. 87\/3 Western Research Laboratory.  Kent C. A. and Mogul J. C. 1987. Fragmentation Considered Harmful. Res. rep. 87\/3 Western Research Laboratory.","DOI":"10.1145\/55482.55524"},{"key":"e_1_2_1_41_1","doi-asserted-by":"crossref","unstructured":"Kent S. and Seo K. 2005. Security architecture for the Internet protocol. RFC 4301 (Proposed Standard). The Internet Society.  Kent S. and Seo K. 2005. Security architecture for the Internet protocol. RFC 4301 (Proposed Standard). The Internet Society.","DOI":"10.17487\/rfc4301"},{"key":"e_1_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1109\/49.839934"},{"key":"e_1_2_1_43_1","doi-asserted-by":"crossref","unstructured":"Killalea T. 2000. Recommended Internet service provider security services and procedures. RFC 3013 (Best Current Practice). The Internet Society.   Killalea T. 2000. Recommended Internet service provider security services and procedures. RFC 3013 (Best Current Practice). The Internet Society.","DOI":"10.17487\/rfc3013"},{"key":"e_1_2_1_44_1","unstructured":"Klein A. 2007. BIND 9 DNS cache poisoning. Tech. rep. Trusteer Ltd.  Klein A. 2007. BIND 9 DNS cache poisoning. Tech. rep. Trusteer Ltd."},{"key":"e_1_2_1_45_1","volume-title":"Proceedings of the 15th Conference on USENIX Security Symposium.","author":"Lad M."},{"key":"e_1_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/972374.972383"},{"key":"e_1_2_1_47_1","volume-title":"Proceedings of BSDCo., S. J. Leffler, Ed., USENIX, 89--97","author":"Lemon J.","year":"2002"},{"key":"e_1_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2007.09.024"},{"key":"e_1_2_1_49_1","doi-asserted-by":"crossref","unstructured":"Mogul J. and Deering S. 1990. Path MTU discovery. RFC 1191 (Draft Standard). The Internet Society.   Mogul J. and Deering S. 1990. Path MTU discovery. RFC 1191 (Draft Standard). The Internet Society.","DOI":"10.17487\/rfc1191"},{"key":"e_1_2_1_50_1","volume-title":"Proceedings of the 10th USENIX Security Symposium.","author":"Moore D."},{"key":"e_1_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1145\/1028788.1028794"},{"key":"e_1_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1145\/383059.383061"},{"key":"e_1_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1145\/505659.505664"},{"key":"e_1_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1145\/1216370.1216373"},{"key":"e_1_2_1_55_1","unstructured":"Postel J. 1981a. Internet control message protocol. RFC 792 (Standard). Updated by RFCs 950 4884. The Internet Society.   Postel J. 1981a. Internet control message protocol. RFC 792 (Standard). Updated by RFCs 950 4884. The Internet Society."},{"key":"e_1_2_1_56_1","doi-asserted-by":"crossref","unstructured":"Postel J. 1981b. Internet protocol. RFC 791 (Standard). Updated by RFC 1349. The Internet Society.  Postel J. 1981b. Internet protocol. RFC 791 (Standard). Updated by RFC 1349. The Internet Society.","DOI":"10.17487\/rfc0791"},{"key":"e_1_2_1_57_1","doi-asserted-by":"crossref","unstructured":"Richardson M. 2005. A method for storing IPsec keying material in DNS. RFC 4025 (Proposed Standard). The Internet Society.  Richardson M. 2005. A method for storing IPsec keying material in DNS. RFC 4025 (Proposed Standard). The Internet Society.","DOI":"10.17487\/rfc4025"},{"key":"e_1_2_1_58_1","doi-asserted-by":"crossref","unstructured":"Richardson M. and Redelmeier D. 2005. Opportunistic encryption using the Internet Key Exchange (IKE). RFC 4322 (Informational). The Internet Society.  Richardson M. and Redelmeier D. 2005. Opportunistic encryption using the Internet Key Exchange (IKE). RFC 4322 (Informational). The Internet Society.","DOI":"10.17487\/rfc4322"},{"key":"e_1_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.1145\/347059.347560"},{"key":"e_1_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.1145\/1102120.1102170"},{"key":"e_1_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.1145\/383059.383060"},{"key":"e_1_2_1_62_1","volume-title":"Proceedings of the Annual Joint Conference of the IEEE Computer and Communications Societies (INFOCOM). 878--886","author":"Song D. X."},{"key":"e_1_2_1_63_1","doi-asserted-by":"crossref","unstructured":"Srisuresh P. and Egevang K. 2001. Traditional IP Network Address Translator (Traditional NAT). RFC 3022 (Informational). The Internet Society.   Srisuresh P. and Egevang K. 2001. Traditional IP Network Address Translator (Traditional NAT). RFC 3022 (Informational). The Internet Society.","DOI":"10.17487\/rfc3022"},{"key":"e_1_2_1_64_1","volume-title":"Proceedings of the European Symposium on Research in Computer Security (ESORICS). 37--52","author":"Studer A."},{"key":"e_1_2_1_65_1","doi-asserted-by":"crossref","unstructured":"Touch J. Black D. and Wang Y. 2008. Problem and applicability statement for Better-Than-Nothing Security (BTNS). RFC 5387 (Informational). The Internet Society.  Touch J. Black D. and Wang Y. 2008. Problem and applicability statement for Better-Than-Nothing Security (BTNS). RFC 5387 (Informational). The Internet Society.","DOI":"10.17487\/rfc5387"},{"key":"e_1_2_1_66_1","doi-asserted-by":"publisher","DOI":"10.1109\/TNET.2006.890133"},{"key":"e_1_2_1_67_1","doi-asserted-by":"publisher","DOI":"10.1109\/NPSEC.2007.4371617"},{"key":"e_1_2_1_68_1","first-page":"15","article-title":"Securing BGP through secure origin BGP","volume":"6","author":"White R.","year":"2003","journal-title":"Internet Protocol J."},{"key":"e_1_2_1_69_1","doi-asserted-by":"crossref","unstructured":"Williams N. and Richardson M. 2008. Better-Than-Nothing security: An unauthenticated mode of IPsec. RFC 5386 (Proposed Standard). The Internet Society.  Williams N. and Richardson M. 2008. Better-Than-Nothing security: An unauthenticated mode of IPsec. RFC 5386 (Proposed Standard). The Internet Society.","DOI":"10.17487\/rfc5386"},{"key":"e_1_2_1_70_1","volume-title":"Proceedings of the IEEE Symposium on Security and Privacy. 130--143","author":"Yaar A."},{"key":"e_1_2_1_71_1","doi-asserted-by":"publisher","DOI":"10.1109\/TNET.2007.914506"}],"container-title":["ACM Transactions on Information and System Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2240276.2240277","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2240276.2240277","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T09:20:52Z","timestamp":1750238452000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2240276.2240277"}},"subtitle":["A Defense Against IP Spoofing and Flooding Attacks"],"short-title":[],"issued":{"date-parts":[[2012,7]]},"references-count":71,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2012,7]]}},"alternative-id":["10.1145\/2240276.2240277"],"URL":"https:\/\/doi.org\/10.1145\/2240276.2240277","relation":{},"ISSN":["1094-9224","1557-7406"],"issn-type":[{"value":"1094-9224","type":"print"},{"value":"1557-7406","type":"electronic"}],"subject":[],"published":{"date-parts":[[2012,7]]},"assertion":[{"value":"2010-09-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2011-11-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2012-07-01","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}