Home / Journals / CMC / Online First / doi:10.32604/cmc.2026.082384
Special Issues
Table of Content

Open Access

ARTICLE

DSPT: Distributed Similar Payload Traceback Based on Bloom Filter

Changsheng Hou1, Xionglve Li2, Bingnan Hou2, Zhiping Cai2, Jingtao Hu1,*, Shuai Ye1, Hao Li1
1 Academy of Military Sciences, Beijing, China
2 College of Computer, National University of Defense Technology, Changsha, China
* Corresponding Author: Jingtao Hu. Email: email

Computers, Materials & Continua https://doi.org/10.32604/cmc.2026.082384

Received 15 March 2026; Accepted 13 July 2026; Published online 05 August 2026

Abstract

Malicious network attacks pose severe threats to cyberspace, and efficient post-incident traceback and forensics techniques are urgently demanded. Existing payload attribution methods mainly support exact matching, while similar-payload schemes suffer from low efficiency and excessive overhead; most are single-node solutions that fail against IP spoofing and stepping-stone attacks, and the distributed Topology-aware Single Packet IP Traceback System (TOPO) relies on full-node cooperation and flooding forwarding, leading to huge overhead and a nearly 100% false positive rate. To mitigate these issues, we propose Distributed Similar Payload Traceback (DSPT), a distributed system that achieves hop-by-hop traceback via upstream cooperative notice without flooding, and uses packet caching and non-shingling to improve the accuracy of malicious traffic and variant tracing. Extensive experiments on real topologies and campus traffic show that DSPT supports efficient traceback for excerpts of different lengths, reduces the false positive rate to below 26% even in similar-payload scenarios, and achieves much lower average false positives and query time than TOPO.

Keywords

IP traceback; similar traffic detection; similar traffic traceback; distributed similar traffic traceback; attack attribution; network security; bloom filter
  • 60

    View

  • 12

    Download

  • 0

    Like

Share Link