Beverly Schwartz

dblp:46/204 · DBLP profile ↗
← Back
7ranked-venue papers
1as first author
0since 2021 · last 2009
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 6Systems, architecture and hardware · 1 · 1 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Computer networks
4 papers
Routing and switching · 39% Internet architecture and protocols · 20% Network management and operations · 20%
Network and information security
1 paper
Network security · 100%

Topics — the 8 heaviest of 8, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Network security
IP traceback
0.012002
Single-packet IP traceback · IEEE/ACM Trans. Netw. 2002
Network security
traffic analysis
0.012002
Single-packet IP traceback · IEEE/ACM Trans. Netw. 2002
Routing and switching › routing protocol
intra-domain routing
0.012001
FIRE: flexible intra-AS routing environment · IEEE J. Sel. Areas Commun. 2001
Internet architecture and protocols › future internet architecture
active networks
0.012000
Smart packets: applying active networks to network management · ACM Trans. Comput. Syst. 2000
Network management and operations
network monitoring
0.012000
Smart packets: applying active networks to network management · ACM Trans. Comput. Syst. 2000
Software-defined and programmable networks
programmable routing
0.012000
FIRE: Flexible intra-AS routing environment · SIGCOMM 2000
Routing and switching
packet forwarding
0.012002
Single-packet IP traceback · IEEE/ACM Trans. Netw. 2002
Routing and switching › routing protocol
link-state routing
0.012001
FIRE: flexible intra-AS routing environment · IEEE J. Sel. Areas Commun. 2001

Methods — techniques the papers use, named apart from their topics

simulation · 0.1hashing · 0.1java implementation · 0.0safe language design · 0.0packet programming · 0.0
YearPublicationVenuePosition
2009 An architecture for scalable network defense
abstract
We describe a novel architecture for network defense designed for scaling to very high data rates (100 Gb/s) and very large user populations. Scaling requires both efficient attack detection algorithms as well as appropriate an execution environment. Our architecture considers the time budget of traffic data extraction and algorithmic processing, provides a suite of detection algorithms - each designed to present different and complementary views of the data-that generate many ¿traffic events,¿ and reduces false positives by correlating these traffic events into benign or malicious hypotheses.
W. Timothy Strayer, Walter C. Milliken, Ronald J. Watro, Walt Heimerdinger, Steven A. Harp, Robert P. Goldman, Dustin Spicuzza, Beverly Schwartz, David Mankins, Derrick Kong, Pieter Mudge Zatko
LCN8
2007 Efficient Multi-Dimensional Flow Correlation
abstract
Flow correlation algorithms compare flows to determine similarity, and are especially useful and well studied for detecting flow chains through "stepping stone" hosts. Most correlation algorithms use only one characteristic and require all values in the correlation matrix (the correlation value of all flows to all other flows) to be updated on every event. We have developed an algorithm that tracks multiple (n) characteristics per flow, and requires updating only the flow's n values upon an event, not all the values for all the flows. The n correlation values are used as coordinates for a point in n-space; two flows are considered correlated if there is a very small Euclidean distance between them. Our results show that this algorithm is efficient in space and compute time, is resilient against anomalies in the flow, and has uses outside of stepping stone detection.
W. Timothy Strayer, Christine E. Jones, Beverly Schwartz, Sarah Edwards, Walter C. Milliken, Alden W. Jackson
LCN3
2005 Architecture for Multi-Stage Network Attack Traceback
abstract
Attacks can originate from anywhere in the network but there is little the network can tell operators about where the attacker is located. Packet traceback techniques have been proposed to find the source of one or more IP packets, but some attackers use multiple remote login sessions, or stepping stones, to increase obfuscation. IP packet traceback can only find the source of one of the several connections in the stepping stone connection chain. Stealthy tracing attackers research light trace (STARLlTE) is a customization and significant extension to BBN's source path isolation engine (SPlE.) The goal of STARLlTE was to construct a prototype to integrate single packet traceback with stepping stone detection. The resulting prototype traces a packet to an ingress router, and then discovers if the flow of that packet is related to a flow in another connection. A successful correlation can then be continued until an ultimate source is located
W. Timothy Strayer, Christine E. Jones, Beverly Schwartz
LCN3
2002 Single-packet IP traceback
abstract
The design of the IP protocol makes it difficult to reliably identify the originator of an IP packet. Even in the absence of any deliberate attempt to disguise a packet's origin, widespread packet forwarding techniques such as NAT and encapsulation may obscure the packet's true source. Techniques have been developed to determine the source of large packet flows, but, to date, no system has been presented to track individual packets in an efficient, scalable fashion. We present a hash-based technique for IP traceback that generates audit trails for traffic within the network, and can trace the origin of a single IP packet delivered by the network in the recent past. We demonstrate that the system is effective, space efficient (requiring approximately 0.5% of the link capacity per unit time in storage), and implementable in current or next-generation routing hardware. We present both analytic and simulation results showing the system's effectiveness.
Alex C. Snoeren, Craig Partridge, Christine E. Jones, Fabrice Tchakountio, Beverly Schwartz, Stephen T. Kent, W. Timothy Strayer
IEEE/ACM Trans. Netw.6
2001 FIRE: flexible intra-AS routing environment
abstract
Current routing protocols are monolithic, specifying the algorithm used to construct forwarding tables, the metric used by the algorithm (generally some form of hop count), and the protocol used to distribute these metrics as an integrated package. The flexible intra-AS routing environment (FIRE) is a link-state, intradomain routing protocol that decouples these components. FIRE supports run-time-programmable algorithms and metrics over a secure link-state distribution protocol. By allowing the network operator to dynamically reprogram both the properties being advertised and the routing algorithms used to construct forwarding tables, FIRE enables the development and deployment of novel routing algorithms without the need for a new protocol to distribute state. FIRE supports multiple concurrent routing algorithms and metrics, each constructing separate forwarding tables. By using operator-specified packet filters, separate classes of traffic may be routed using completely different routing algorithms, all supported by a single routing protocol. This paper presents an overview of FIRE, focusing particularly on FIRE's novel aspects with respect to traditional routing protocols. We consider deploying several current unicast and multicast routing algorithms in FIRE, and describe our Java-based implementation.
Craig Partridge, Alex C. Snoeren, W. Timothy Strayer, Beverly Schwartz, Matthew Condell, Isidro Castiñeyra
IEEE J. Sel. Areas Commun.4
2000 FIRE: Flexible intra-AS routing environment
abstract
Current routing protocols are monolithic, specifying the algorithm used to construct forwarding tables, the metric used by the algorithm (generally some form of hop-count), and the protocol used to distribute these metrics as an integrated package. The Flexible Intra-AS Routing Environment (FIRE) is a link-state, intra-domain routing protocol that decouples these components. FIRE supports run-time-pro- grammable algorithms and metrics over a secure link-state distribution protocol. By allowing the network operator to dynamically reprogram both the information being advertised and the routing algorithm used to construct forwarding tables in Java, FIRE enables the development and deployment of novel routing algorithms without the need for a new protocol to distribute state. FIRE supports multiple concurrent routing algorithms and metrics, each constructing separate forwarding tables. By using operator-specified packet filters, separate classes of traffic are routed using completely different routing algorithms, all supported by a single routing protocol.
Craig Partridge, Alex C. Snoeren, W. Timothy Strayer, Beverly Schwartz, Matthew Condell, Isidro Castiñeyra
SIGCOMM4
2000 Smart packets: applying active networks to network management
abstract
This article introduces Smart Packets and describes the smart Packets architecture, the packet formats, the language and its design goals, and security considerations. Smart Packets is an Active Networks project focusing on applying active networks technology to network management and monitoring. Messages in active networks are programs that are executed at nodes on the path to one or more target hosts. Smart Packets programs are written in a tightly encoded, safe language specifically designed to support network management and avoid dangerous constructs and accesses. Smart Packets improves the management of large complex networks by (1) moving management decision points closer to the node being managed, (2) targeting specific aspects of the node for information rather than exhaustive collection via polling, and (3) abstracting the management concepts to language constructs, allowing nimble network control.
Beverly Schwartz, Alden W. Jackson, W. Timothy Strayer, Wenyi Zhou, R. Dennis Rockwell, Craig Partridge
ACM Trans. Comput. Syst.1