TY - EJOU AU - Hou, Changsheng AU - Li, Xionglve AU - Hou, Bingnan AU - Cai, Zhiping AU - Hu, Jingtao AU - Ye, Shuai AU - Li, Hao TI - DSPT: Distributed Similar Payload Traceback Based on Bloom Filter T2 - Computers, Materials \& Continua PY - VL - IS - SN - 1546-2226 AB - Malicious network attacks pose severe threats to cyberspace, and efficient post-incident traceback and forensics techniques are urgently demanded. Existing payload attribution methods mainly support exact matching, while similar-payload schemes suffer from low efficiency and excessive overhead; most are single-node solutions that fail against IP spoofing and stepping-stone attacks, and the distributed Topology-aware Single Packet IP Traceback System (TOPO) relies on full-node cooperation and flooding forwarding, leading to huge overhead and a nearly 100% false positive rate. To mitigate these issues, we propose Distributed Similar Payload Traceback (DSPT), a distributed system that achieves hop-by-hop traceback via upstream cooperative notice without flooding, and uses packet caching and non-shingling to improve the accuracy of malicious traffic and variant tracing. Extensive experiments on real topologies and campus traffic show that DSPT supports efficient traceback for excerpts of different lengths, reduces the false positive rate to below 26% even in similar-payload scenarios, and achieves much lower average false positives and query time than TOPO. KW - IP traceback; similar traffic detection; similar traffic traceback; distributed similar traffic traceback; attack attribution; network security; bloom filter DO - 10.32604/cmc.2026.082384