VLDB 2026 Research / reviewers in the wild / expert
Clay Shields
dblp:82/3920
· DBLP profile ↗
28ranked-venue papers
5as first author
0since 2021 · last 2018
0009-0000-3588-1723ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 16 · 1 first-authorComputer networks · 10 · 3 first-authorSystems, architecture and hardware · 2 · 1 first-author
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
14 papers |
Network security · 48% Digital forensics and information hiding · 30% Cyber-physical and IoT security · 13% | |
| Computer networks
8 papers |
Network measurement and analytics · 43% Routing and switching · 37% Internet architecture and protocols · 15% | |
| Artificial intelligence
1 paper |
Speech recognition and synthesis · 100% |
Topics — the 24 heaviest of 29, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Digital forensics and information hiding › digital forensics
network forensics |
0.4 | 4 | 2014 | Efficient Tagging of Remote Peers during Child Pornography Investigations · IEEE Trans. Dependable Secur. Comput. 2014 Strengthening forensic investigations of child pornography on P2P networks · CoNEXT 2010 Providing Process Origin Information to Aid in Network Traceback · USENIX ATC, General Track 2002 |
Network security
traffic analysis |
0.3 | 4 | 2014 | Efficient Tagging of Remote Peers during Child Pornography Investigations · IEEE Trans. Dependable Secur. Comput. 2014 IP covert timing channels: design and detection · CCS 2004 Defending Anonymous Communications Against Passive Logging Attack · S&P 2003 |
Cyber-physical and IoT security
voice assistant security |
0.2 | 1 | 2016 | Hidden Voice Commands · USENIX Security Symposium 2016 |
Digital forensics and information hiding
digital forensics |
0.2 | 1 | 2014 | Efficient Tagging of Remote Peers during Child Pornography Investigations · IEEE Trans. Dependable Secur. Comput. 2014 |
Network security
anonymity networks |
0.1 | 3 | 2003 | Defending Anonymous Communications Against Passive Logging Attack · S&P 2003 An Analysis of the Degradation of Anonymous Protocols · NDSS 2002 A protocol for anonymous communication over the Internet · CCS 2000 |
Network security
routing security |
0.1 | 2 | 2005 | Authenticated routing for ad hoc networks · IEEE J. Sel. Areas Commun. 2005 A Secure Routing Protocol for Ad Hoc Networks · ICNP 2002 |
Network security
covert channel |
0.0 | 1 | 2004 | IP covert timing channels: design and detection · CCS 2004 |
Network security › intrusion detection and prevention
covert channel detection |
0.0 | 1 | 2004 | IP covert timing channels: design and detection · CCS 2004 |
Network security › covert channel
covert timing channel |
0.0 | 1 | 2004 | IP covert timing channels: design and detection · CCS 2004 |
Routing and switching
multicast routing |
0.0 | 3 | 1999 | The Protocol for Hierarchical Multicast Routing · PODC 1998 The Ordered Core Based Tree Protocol · INFOCOM 1997 KHIP - A Scalable Protocol for Secure Multicast Routing · SIGCOMM 1999 |
Privacy and data protection
anonymity |
0.0 | 2 | 2002 | Responder Anonymity and Anonymous Peer-to-Peer File Sharing · ICNP 2001 An Analysis of the Degradation of Anonymous Protocols · NDSS 2002 |
Authentication and access control
authentication |
0.0 | 1 | 2002 | A Secure Routing Protocol for Ad Hoc Networks · ICNP 2002 |
Network security
IP traceback |
0.0 | 1 | 2002 | Providing Process Origin Information to Aid in Network Traceback · USENIX ATC, General Track 2002 |
Operating systems › resource management
process management |
0.0 | 1 | 2002 | Providing Process Origin Information to Aid in Network Traceback · USENIX ATC, General Track 2002 |
Network security › anonymity networks
anonymous communication protocol |
0.0 | 1 | 2000 | A protocol for anonymous communication over the Internet · CCS 2000 |
Cryptographic protocols and secure computation › key management
key distribution |
0.0 | 1 | 1999 | KHIP - A Scalable Protocol for Secure Multicast Routing · SIGCOMM 1999 |
Routing and switching › multicast routing
hierarchical multicast routing |
0.0 | 1 | 1998 | The Protocol for Hierarchical Multicast Routing · PODC 1998 |
Internet architecture and protocols › multicast
multicast protocols |
0.0 | 1 | 1997 | The Ordered Core Based Tree Protocol · INFOCOM 1997 |
Routing and switching
ad hoc network routing |
0.0 | 1 | 2005 | Authenticated routing for ad hoc networks · IEEE J. Sel. Areas Commun. 2005 |
Cryptographic primitives and cryptanalysis
public-key cryptography |
0.0 | 1 | 2005 | Authenticated routing for ad hoc networks · IEEE J. Sel. Areas Commun. 2005 |
Wireless networking
mobile ad hoc networks |
0.0 | 1 | 2002 | A Secure Routing Protocol for Ad Hoc Networks · ICNP 2002 |
Internet architecture and protocols
peer-to-peer networks |
0.0 | 1 | 2001 | Responder Anonymity and Anonymous Peer-to-Peer File Sharing · ICNP 2001 |
Routing and switching
inter-domain routing |
0.0 | 1 | 1998 | The Protocol for Hierarchical Multicast Routing · PODC 1998 |
Routing and switching › routing
routing instability |
0.0 | 1 | 1997 | The Ordered Core Based Tree Protocol · INFOCOM 1997 |
Methods — techniques the papers use, named apart from their topics
adversarial examples · 0.5network measurement · 0.2application-level tagging · 0.2network-level identifier analysis · 0.2application-level identifier analysis · 0.2public-key cryptography · 0.1certificate-based authentication · 0.1simulation · 0.1timing channel design · 0.0regularity detection · 0.0cryptographic hashing · 0.0multicast routing · 0.0hierarchical key management · 0.0virtual routers · 0.0shared tree routing · 0.0
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2018 | DeDoS: Defusing DoS with Dispersion Oriented SoftwareabstractThis paper presents DeDoS, a novel platform for mitigating asymmetric DoS attacks. These attacks are particularly challenging since even attackers with limited resources can exhaust the resources of well-provisioned servers. DeDoS offers a framework to deploy code in a highly modular fashion. If part of the application stack is experiencing a DoS attack, DeDoS can massively replicate only the affected component, potentially across many machines. This allows scaling of the impacted resource separately from the rest of the application stack, so that resources can be precisely added where needed to combat the attack. Our evaluation results show that DeDoS incurs reasonable overheads in normal operations, and that it significantly outperforms standard replication techniques when defending against a range of asymmetric attacks. Henri Maxime Demoulin, Tavish Vaidya, Isaac Pedisich, Bob DiMaiolo, Jingyu Qian, Yuankai Zhang 0001, Ang Chen 0001, Andreas Haeberlen, Boon Thau Loo, Linh T. X. Phan, Micah Sherr, Clay Shields, Wenchao Zhou |
ACSAC | 13 |
| 2016 | Dispersing Asymmetric DDoS Attacks with SplitStackabstractThis paper presents SplitStack, an architecture targeted at mitigating asymmetric DDoS attacks. These attacks are particularly challenging, since attackers can use a limited amount of resources to trigger exhaustion of a particular type of system resource on the server side. SplitStack resolves this by splitting the monolithic stack into many separable components called minimum splittable units (MSUs). If part of the application stack is experiencing a DDoS attack, SplitStack massively replicates just the affected MSUs, potentially across many machines. This allows scaling of the impacted resource separately from the rest of the application stack, so that resources can be precisely added where needed to combat the attack. We validate SplitStack via a preliminary case study, and show that it outperforms naive replication in defending against asymmetric attacks. Ang Chen 0001, Akshay Sriraman, Tavish Vaidya, Yuankai Zhang 0001, Andreas Haeberlen, Boon Thau Loo, Linh T. X. Phan, Micah Sherr, Clay Shields, Wenchao Zhou |
HotNets | 9 |
| 2016 | Hidden Voice Commands
Nicholas Carlini, Pratyush Mishra 0001, Tavish Vaidya, Yuankai Zhang 0001, Micah Sherr, Clay Shields, David A. Wagner 0001, Wenchao Zhou |
USENIX Security Symposium | 6 |
| 2015 | Accountable wiretapping - or - I know they can hear you nowabstractAbstract In many democratic countries, Communications Assistance for Law Enforcement Act (CALEA) wiretaps are used by law enforcement agencies to perform investigations and gather evidence for legal procedures. However, existing CALEA wiretap implementations are often engineered with the assumption that wiretap operators are trustworthy and wiretap targets do not attempt to evade the wiretap. Although it may be possible to construct more robust wiretap architectures by reengineering significant portions of the telecommunications infrastructure, such efforts are prohibitively costly. This paper instead proposes a lightweight accountable wiretapping system for enabling secure audits of existing CALEA wiretapping systems. Our proposed system maintains a tamper-evident encrypted log over wiretap events, enforces access controls over wiretap records, and enables privacy-preserving aggregate queries and compliance checks. We demonstrate using campus-wide telephone trace data from a large university that our approach provides efficient auditing functionalities while incurring only modest overhead. Based on publicly available wiretap reporting statistics, we conservatively estimate that our architecture can support tamper-evident logging for all of the United States’ ongoing CALEA wiretaps using three commodity PCs. Adam Bates 0001, Kevin R. B. Butler, Micah Sherr, Clay Shields, Patrick Traynor, Dan S. Wallach |
J. Comput. Secur. | 4 |
| 2014 | Efficient Tagging of Remote Peers during Child Pornography InvestigationsabstractMeasurements of the Internet for law enforcement purposes must be forensically valid. We examine the problems inherent in using various network- and application-level identifiers in the context of forensic measurement, as exemplified in the policing of peer-to-peer file sharing networks for sexually exploitative imagery of children. First, we present a one-year measurement performed in the law enforcement context. Our proposed tagging method offers remote machines application- or system-level data that is valid, but which covertly has meaning to investigators. This tagging allows investigators to link network observations with physical evidence in a legal, forensically strong, and valid manner. We present a detailed model and analysis of our method, show how tagging can be used in several specific applications, discuss the general applicability of our method, and detail why the tags are strong evidence of criminal intent and participation in a crime. We then describe the tagging mechanisms that have we implemented using the eMule file sharing client. Marc Liberatore, Brian Neil Levine, Clay Shields, Brian Lynn |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2012 | Accountable Wiretapping -or- I know they can hear you now
Adam Bates 0001, Kevin R. B. Butler, Micah Sherr, Clay Shields, Patrick Traynor, Dan S. Wallach |
NDSS | 4 |
| 2011 | Effective Digital Forensics Research Is Investigator-Centric
Robert J. Walls, Brian Neil Levine, Marc Liberatore, Clay Shields |
HotSec | 4 |
| 2010 | Strengthening forensic investigations of child pornography on P2P networksabstractMeasurements of the Internet for law enforcement pur-poses must be forensically valid. We examine the prob-lems inherent in using various network- and application-level identifiers in the context of forensic measurement, as exemplified in the policing of peer-to-peer file sharing networks for sexually exploitative imagery of children (child pornography). First, we present a five-month mea-surement performed in the law enforcement context. We then show how the identifiers in these measurements can be unreliable, and propose the tagging of remote machines. Our proposed tagging method marks remote machines by providing them with application- or system-level data which is valid, but which covertly has meaning to investigators. This tagging allows investigators to link network observations with physical evidence in a legal, forensically strong, and valid manner. We present a detailed model and analysis of our method, show how tagging can be used in several specific applications, dis-cuss the general applicability of our method, and detail why the tags are strong evidence of criminal intent and participation in a crime. 1. Marc Liberatore, Brian Neil Levine, Clay Shields |
CoNEXT | 3 |
| 2009 | IP Covert Channel DetectionabstractA covert channel can occur when an attacker finds and exploits a shared resource that is not designed to be a communication mechanism. A network covert channel operates by altering the timing of otherwise legitimate network traffic so that the arrival times of packets encode confidential data that an attacker wants to exfiltrate from a secure area from which she has no other means of communication. In this article, we present the first public implementation of an IP covert channel, discuss the subtle issues that arose in its design, and present a discussion on its efficacy. We then show that an IP covert channel can be differentiated from legitimate channels and present new detection measures that provide detection rates over 95%. We next take the simple step an attacker would of adding noise to the channel to attempt to conceal the covert communication. For these noisy IP covert timing channels, we show that our online detection measures can fail to identify the covert channel for noise levels higher than 10%. We then provide effective offline search mechanisms that identify the noisy channels. Serdar Cabuk, Carla E. Brodley, Clay Shields |
ACM Trans. Inf. Syst. Secur. | 3 |
| 2008 | Passive-Logging Attacks Against Anonymous Communications SystemsabstractUsing analysis, simulation, and experimentation, we examine the threat against anonymous communications posed by passive-logging attacks. In previous work, we analyzed the success of such attacks under various assumptions. Here, we evaluate the effects of these assumptions more closely. First, we analyze the Onion Routing-based model used in prior work in which a fixed set of nodes remains in the system indefinitely. We show that for this model, by removing the assumption of uniformly random selection of nodes for placement in the path, initiators can greatly improve their anonymity. Second, we show by simulation that attack times are significantly lower in practice than bounds given by analytical results from prior work. Third, we analyze the effects of a dynamic membership model, in which nodes are allowed to join and leave the system; we show that all known defenses fail more quickly when the assumption of a static node set is relaxed. Fourth, intersection attacks against peer-to-peer systems are shown to be an additional danger, either on their own or in conjunction with the predecessor attack. Finally, we address the question of whether the regular communication patterns required by the attacks exist in real traffic. We collected and analyzed the Web requests of users to determine the extent to which basic patterns can be found. We show that, for our study, frequent and repeated communication to the same Web site is common. Matthew Wright 0001, Micah Adler, Brian Neil Levine, Clay Shields |
ACM Trans. Inf. Syst. Secur. | 4 |
| 2006 | Internet security
Brian Neil Levine, Clay Shields |
Comput. Commun. | 2 |
| 2005 | Authenticated routing for ad hoc networksabstractInitial work in ad hoc routing has considered only the problem of providing efficient mechanisms for finding paths in very dynamic networks, without considering security. Because of this, there are a number of attacks that can be used to manipulate the routing in an ad hoc network. In this paper, we describe these threats, specifically showing their effects on ad hoc on-demand distance vector and dynamic source routing. Our protocol, named authenticated routing for ad hoc networks (ARAN), uses public-key cryptographic mechanisms to defeat all identified attacks. We detail how ARAN can secure routing in environments where nodes are authorized to participate but untrusted to cooperate, as well as environments where participants do not need to be authorized to participate. Through both simulation and experimentation with our publicly available implementation, we characterize and evaluate ARAN and show that it is able to effectively and efficiently discover secure routes within an ad hoc network. Kimaya Sanzgiri, D. LaFlamme, Bridget Dahill, Brian Neil Levine, Clay Shields, Elizabeth M. Belding |
IEEE J. Sel. Areas Commun. | 5 |
| 2004 | IP covert timing channels: design and detectionabstractA network covert channel is a mechanism that can be used to leak information across a network in violation of a security policy and in a manner that can be difficult to detect. In this paper, we describe our implementation of a covert network timing channel, discuss the subtle issues that arose in its design, and present performance data for the channel. We then use our implementation as the basis for our experiments in its detection. We show that the regularity of a timing channel can be used to differentiate it from other traffic and present two methods of doing so and measures of their efficiency. We also investigate mechanisms that attackers might use to disrupt the regularity of the timing channel, and demonstrate methods of detection that are effective against them. Serdar Cabuk, Carla E. Brodley, Clay Shields |
CCS | 3 |
| 2004 | Providing process origin information to aid in computer forensic investigationsabstractThe number of computer attacks has been growing dramatically as the Internet has grown. Attackers currently have little or no disincentive to conducting attacks because they are able to hide their location effectively by creating a chain of connections through a series of hosts. This method is effective because most current host audit systems do not maintain enough information to allow association of incoming and outgoing network connections. In this paper, we introduce an inexpensive method that allows both on-line and forensic matching of incoming and outgoing network traffic. Our method makes small modifications to the operating system that associate origin information with each process in the system process table, and enhances the audit information by logging the origin and destination of network sockets. We present implementation results, show that our method can effectively record origin information about a variety of attacks, and describe the limitations of our approach. Florian P. Buchholz, Clay Shields |
J. Comput. Secur. | 2 |
| 2004 | The session token protocol for forensics and tracebackabstractIn this paper we present the Session Token Protocol (STOP), a new protocol that can assist in the forensic analysis of a computer involved in malicious network activity. It has been designed to help automate the process of tracing attackers who log on to a series of hosts to hide their identity. STOP utilizes the Identification Protocol infrastructure, improving both its capabilities and user privacy. On request, the STOP protocol saves user-level and application-level data associated with a particular TCP connection and returns a random token specifically related to that session. The saved data are not revealed to the requester unless the token is returned to the local administrator, who verifies the legitimacy of the need for the release of information. The protocol supports recursive traceback requests to gather information about the entire path of a connection. This allows an incident investigator to trace attackers to their home systems, but does not violate the privacy of normal users. This paper details the new protocol and presents implementation and performance results. Brian D. Carrier, Clay Shields |
ACM Trans. Inf. Syst. Secur. | 2 |
| 2004 | The predecessor attack: An analysis of a threat to anonymous communications systemsabstractThere have been a number of protocols proposed for anonymous network communication. In this paper, we investigate attacks by corrupt group members that degrade the anonymity of each protocol over time. We prove that when a particular initiator continues communication with a particular responder across path reformations, existing protocols are subject to the attack. We use this result to place an upper bound on how long existing protocols, including Crowds, Onion Routing, Hordes, Web Mixes, and DC-Net, can maintain anonymity in the face of the attacks described. This provides a basis for comparing these protocols against each other. Our results show that fully connected DC-Net is the most resilient to these attacks, but it suffers from scalability issues that keep anonymity group sizes small. We also show through simulation that the underlying topography of the DC-Net affects the resilience of the protocol: as the number of neighbors a node has increases the strength of the protocol increases, at the cost of higher communication overhead. Matthew Wright 0001, Micah Adler, Brian Neil Levine, Clay Shields |
ACM Trans. Inf. Syst. Secur. | 4 |
| 2003 | Defending Anonymous Communications Against Passive Logging AttackabstractWe study the threat that passive logging attacks pose to anonymous communications. Previous work analyzed these attacks under limiting assumptions. We first describe a possible defense that comes from breaking the assumption of uniformly random path selection. Our analysis shows that the defense improves anonymity in the static model, where nodes stay in the system, but fails in a dynamic model, in which nodes leave and join. Additionally, we use the dynamic model to show that the intersection attack creates a vulnerability in certain peer-to-peer systems for anonymous communications. We present simulation results that show that attack times are significantly lower in practice than the upper bounds given by previous work. To determine whether users' Web traffic has communication patterns required by the attacks, we collected and analyzed the Web requests of users. We found that, for our study frequent and repeated communication to the same Web site is common. Matthew Wright 0001, Micah Adler, Brian Neil Levine, Clay Shields |
S&P | 4 |
| 2002 | A Secure Routing Protocol for Ad Hoc NetworksabstractMost recent ad hoc network research has focused on providing routing services without considering security. We detail security threats against ad hoc routing protocols, specifically examining AODV and DSR. In light of these threats, we identify three different environments with distinct security requirements. We propose a solution to one, the managed-open scenario where no network infrastructure is pre-deployed, but a small amount of prior security coordination is expected. Our protocol, authenticated routing for ad hoc networks (ARAN), is based on certificates and successfully defeats all identified attacks. Kimaya Sanzgiri, Bridget Dahill, Brian Neil Levine, Clay Shields, Elizabeth M. Belding |
ICNP | 4 |
| 2002 | A Recursive Session Token Protocol for use in Computer Forensics and TCP TracebackabstractWe introduce a new protocol designed to assist in the forensic investigation of malicious network-based activity, specifically addressing the stepping-stone scenario in which an attacker uses a chain of connections through many hosts to hide his or her identity. Our protocol, the Session TOken Protocol (STOP), enhances the Identification Protocol (ident) infrastructure by sending recursive requests to previous hosts on the connection chain. The protocol has been designed to protect user's privacy by returning a token that is a hash of connection information; a system administrator can later decide whether to release the information relating to the token depending on the circumstances of the request. Brian D. Carrier, Clay Shields |
INFOCOM | 2 |
| 2002 | An Analysis of the Degradation of Anonymous Protocols
Matthew Wright 0001, Micah Adler, Brian Neil Levine, Clay Shields |
NDSS | 4 |
| 2002 | Providing Process Origin Information to Aid in Network Traceback
Florian P. Buchholz, Clay Shields |
USENIX ATC, General Track | 2 |
| 2002 | Hordes: a Multicast-Based Protocol for AnonymityabstractWith widespread acceptance of the Internet as a public medium for communication and information retrieval, there has been rising concern that the personal privacy of users can be eroded by cooperating network entities. A technical solution to maintaining privacy is to provide anonymity. We present a protocol for initiator anonymity called Hordes, which uses forwarding mechanisms similar to those used in previous protocols for sending data, but is the first protocol to make use of multicast routing to anonymously receive data. We show this results in shorter transmission latencies and requires less work of the protocol participants, in terms of the messages processed. We also present a comparison of the security and anonymity of Hordes with previous protocols, using the first quantitative definition of anonymity and unlinkability. Our analysis shows that Hordes provides anonymity in a degree similar to that of Crowds and Onion Routing, but also that Hordes has numerous performance advantages. Brian Neil Levine, Clay Shields |
J. Comput. Secur. | 2 |
| 2001 | Responder Anonymity and Anonymous Peer-to-Peer File SharingabstractData transfer over TCP/IP provides no privacy for network users. Previous research in anonymity has focused on the provision of initiator anonymity. We explore methods of adapting existing initiator-anonymous protocols to provide responder anonymity and mutual anonymity. We present anonymous peer-to-peer file sharing (APFS) protocols, which provide mutual anonymity for peer-to-peer file sharing. APFS addresses the problem of long-lived Internet services that may outlive the degradation present in current anonymous protocols. One variant of APFS makes use of unicast communication, but requires a central coordinator to bootstrap the protocol. A second variant takes advantage of multicast routing to remove the need for any central coordination point. We compare the TCP performance of the APFS protocol to existing overt file sharing systems such as Napster. In providing anonymity, APFS can double transfer times and requires that additional traffic be carried by peers, but this overhead is constant with the size of the session. V. Scarlata, Brian Neil Levine, Clay Shields |
ICNP | 3 |
| 2000 | A protocol for anonymous communication over the InternetabstractWith the growth and acceptance of the Internet, there has been increased interest in maintaining anonymity in the network. This paper presents a new protocol for initiator anonymity called Hordes, which uses forwarding mechanisms similar to those used in previous protocols for sending data, but is the rst protocol to make use of the anonymity inherent in multicast routing to receive data. We show this results in shorter transmission latencies and requires less work of the protocol participants, in terms of the messages processed. We also present a comparison of the security and anonymity of Hordes with previous protocols, using the rst quantitative de nition of anonymity and unlinkability. Our analysis shows that Hordes provides anonymity in a degree similar to that of Crowds and Onion Routing, but also that Hordes has numerous performance advantages. Clay Shields, Brian Neil Levine |
CCS | 1 |
| 2000 | HIP - a protocol for hierarchical multicast routing
Clay Shields, J. J. Garcia-Luna-Aceves |
Comput. Commun. | 1 |
| 1999 | KHIP - A Scalable Protocol for Secure Multicast RoutingabstractWe present Keyed HIP (KHIP), a secure, hierarchical multicast routing protocol. We show that other shared-tree multicast routing protocols are subject to attacks against the multicast routing infrastructure that can isolate receivers or domains or introduce loops into the structure of the multicast routing tree. KHIP changes the multicast routing model so that only trusted members are able to join the multicast tree. This protects the multicast routing against attacks that could form branches to unauthorized receivers, prevents replay attacks and limits the effects of flooding attacks. Untrusted routers that are present on the path between trusted routers cannot change the routing and can mount no denial-of-service attack stronger than simply dropping control messages. KHIP also provides a simple mechanism for distributing data encryption keys while adding little overhead to the protocol. Clay Shields, J. J. Garcia-Luna-Aceves |
SIGCOMM | 1 |
| 1998 | The Protocol for Hierarchical Multicast RoutingabstractThis paper presents a new, exible approach to inter-domain multicast routing. The HIP protocol introduces the idea of \\virtual routers" as a method of organizing the control of an entire domain so as to appear as a single router on a higher-level shared tree. HIP then routes between domains using the Ordered Core Based Tree (OCBT) protocol, and allows recursive application of virtual routers to create a multi-leveled hierarchy while providing ecient methods of distributing the location of the center point for the tree. The advantages of this approach include improved robustness, the ability to route between heterogeneous domains, and a signicant reduction in the amount of bandwidth consumed in control trac and in the amount of state stored at each router over existing hierarchical multicast protocols. 1 Introduction There are two compelling reasons for developing hierarchical multicast routing protocols. The rst is to provide a means of routing between heterogeneous domains that m... Clay Shields, J. J. Garcia-Luna-Aceves |
PODC | 1 |
| 1997 | The Ordered Core Based Tree ProtocolabstractThis paper presents a new protocol, the ordered core based tree (OCBT) protocol, which remedies several shortcomings of the core based tree (CBT) multicast protocol. We show that the CBT protocol can form loops during periods of routing instability, and that it can consistently fail to build a connected multicast tree, even when the underlying routing is stable. The OCBT protocol provably eliminates these deficiencies and reduces the latency of tree repair following a link or core failure. The OCBT also improves scalability by allowing flexible placement of the cores that serve as points of connection to a multicast tree. Simulation results show that the amount of control traffic in OCBT is comparable to that in CBT. Clay Shields, J. J. Garcia-Luna-Aceves |
INFOCOM | 1 |