Open Access
ARTICLE
DSPT: Distributed Similar Payload Traceback Based on Bloom Filter
1 Academy of Military Sciences, Beijing, China
2 College of Computer, National University of Defense Technology, Changsha, China
* Corresponding Author: Jingtao Hu. Email:
Computers, Materials & Continua 2026, 89(1), 79 https://doi.org/10.32604/cmc.2026.082384
Received 15 March 2026; Accepted 13 July 2026; Issue published 13 August 2026
Abstract
Malicious network attacks pose severe threats to cyberspace, and efficient post-incident traceback and forensics techniques are urgently demanded. Existing payload attribution methods mainly support exact matching, while similar-payload schemes suffer from low efficiency and excessive overhead; most are single-node solutions that fail against IP spoofing and stepping-stone attacks, and the distributed Topology-aware Single Packet IP Traceback System (TOPO) relies on full-node cooperation and flooding forwarding, leading to huge overhead and a nearly 100% false positive rate. To mitigate these issues, we propose Distributed Similar Payload Traceback (DSPT), a distributed system that achieves hop-by-hop traceback via upstream cooperative notice without flooding, and uses packet caching and non-shingling to improve the accuracy of malicious traffic and variant tracing. Extensive experiments on real topologies and campus traffic show that DSPT supports efficient traceback for excerpts of different lengths, reduces the false positive rate to below 26% even in similar-payload scenarios, and achieves much lower average false positives and query time than TOPO.Keywords
Cite This Article
Copyright © 2026 The Author(s). Published by Tech Science Press.This work is licensed under a Creative Commons Attribution 4.0 International License , which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.


Submit a Paper
Propose a Special lssue
View Full Text
Download PDF
Downloads
Citation Tools