W. Timothy Strayer

dblp:55/691 · also Tim Strayer · DBLP profile ↗
← Back
23ranked-venue papers
11as first author
0since 2021 · last 2018
0000-0002-5025-133XORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 16 · 9 first-authorSystems, architecture and hardware · 3

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Computer networks
4 papers
Routing and switching · 39% Internet architecture and protocols · 20% Network management and operations · 20%
Network and information security
1 paper
Network security · 100%
Computer architecture, parallel and distributed computing, and storage systems
2 papers
Parallel and multicore computing · 83% High-performance computing · 17%
Software engineering, system software, and programming languages
1 paper
Runtime systems and virtual machines · 77% Compilers and program optimization · 23%

Topics — the 13 heaviest of 14, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Network security
IP traceback
0.012002
Single-packet IP traceback · IEEE/ACM Trans. Netw. 2002
Network security
traffic analysis
0.012002
Single-packet IP traceback · IEEE/ACM Trans. Netw. 2002
Routing and switching › routing protocol
intra-domain routing
0.012001
FIRE: flexible intra-AS routing environment · IEEE J. Sel. Areas Commun. 2001
Internet architecture and protocols › future internet architecture
active networks
0.012000
Smart packets: applying active networks to network management · ACM Trans. Comput. Syst. 2000
Network management and operations
network monitoring
0.012000
Smart packets: applying active networks to network management · ACM Trans. Comput. Syst. 2000
Software-defined and programmable networks
programmable routing
0.012000
FIRE: Flexible intra-AS routing environment · SIGCOMM 2000
Parallel and multicore computing › parallel programming models
object-oriented parallel programming
0.021996
Portable Run-Time Support for Dynamic Object-Oriented Parallel Processing · ACM Trans. Comput. Syst. 1996
A Parallel Object-Oriented Framework for Stencil Algorithms · HPDC 1993
Runtime systems and virtual machines
parallel runtime systems
0.011996
Portable Run-Time Support for Dynamic Object-Oriented Parallel Processing · ACM Trans. Comput. Syst. 1996
Parallel and multicore computing
parallel programming models
0.011996
Portable Run-Time Support for Dynamic Object-Oriented Parallel Processing · ACM Trans. Comput. Syst. 1996
Routing and switching
packet forwarding
0.012002
Single-packet IP traceback · IEEE/ACM Trans. Netw. 2002
Parallel and multicore computing › parallel programming models and runtimes
parallel programming frameworks
0.011993
A Parallel Object-Oriented Framework for Stencil Algorithms · HPDC 1993
High-performance computing
stencil computation
0.011993
A Parallel Object-Oriented Framework for Stencil Algorithms · HPDC 1993
Routing and switching › routing protocol
link-state routing
0.012001
FIRE: flexible intra-AS routing environment · IEEE J. Sel. Areas Commun. 2001

Methods — techniques the papers use, named apart from their topics

simulation · 0.1hashing · 0.1object scheduling · 0.0data dependence graph · 0.0java implementation · 0.0safe language design · 0.0packet programming · 0.0object-oriented framework · 0.0inheritance · 0.0
YearPublicationVenuePosition
2018 Content sharing with mobility in an infrastructure-less environment
W. Timothy Strayer, Samuel C. Nelson, Armando Caro, Joud Khoury, Bryan Tedesco, Olivia DeRosa, Carsten Clark, Kolia Sadeghi, Michael Matthews, Jake Kurzer, Philip Lundrigan, Vikas Kawadia, Dorene Ryder, Keith Gremban, Wayne Phoel
Comput. Networks1
2016 Keynote: Evolving Systems for Situational Awareness
abstract
The most basic functions of any organism or organized unit requires understanding the environment. This is accomplished through sensing; for organisms, sensing is an evolved faculty. The same is true for military and first responder units such as squads, who are relying on more sophisticated sensing systems to gain greater situational awareness (SA) in order to more effectively and safely conduct their missions. Adding sensing to the squad, however, only solves part of the problem; there must be an appropriate communications system in place to make full use of the acquired SA information. This talk will explore the use of content-based networking solutions for efficiently distributing the SA information in a decentralized manner.
W. Timothy Strayer
NCA1
2015 Rebound: Decoy routing on asymmetric routes via error messages
abstract
Decoy routing is a powerful circumvention mechanism intended to provide secure communications that cannot be monitored, detected, or disrupted by a third party who controls the user's network infrastructure. Current decoy routing protocols have weaknesses, however: they either make the unrealistic assumption that routes through the network are symmetric (i.e., the router implementing the decoy routing protocol must see all of the traffic, in both directions, from each connection it modifies), or their protocol requires modifying the route taken by packets in connections that use the protocol, and these route changes are detectable by a third party. We present Rebound, a decoy routing protocol that tolerates asymmetric routes without modifying the route taken by any packet that passes through the decoy router, making it more difficult to detect or disrupt than previous decoy routing protocols.
Daniel Ellard, Christine E. Jones, Victoria Manfredi, W. Timothy Strayer, Bishal Thapa, Megan Van Welie, Alden W. Jackson
LCN4
2012 A concept for publish-subscribe information dissemination and networking
abstract
Although IP and its overlying protocols, such as TCP and UDP, are ubiquitous, they were originally designed for point-to-point connections between computers in reasonably fixed locations. They are less suited to mobile networks and broadcast communications. In this paper, we present an alternative to IP that is based on a publish-subscribe approach. The approach that we present combines an application publish-subscribe programming model with a content delivery network, which provides several advantages in certain communication environments, including quality of service based on application level needs; efficient support for reliable broadcast; support for disadvantaged, intermittent, and limited communications; and more efficient reliability and fault tolerance. The paper presents our approach, based on a streamlined Data Distribution Service and simplified Content Delivery Network, a motivating example in which the publish-subscribe based distribution and network provides advantages, and a contrast to TCP/IP in the example context.
Joseph P. Loyall, Matthew Gillen, Karen Zita Haigh, Robert Walsh, Craig Partridge, Gregory Lauer, W. Timothy Strayer
ICC7
2009 An architecture for scalable network defense
abstract
We describe a novel architecture for network defense designed for scaling to very high data rates (100 Gb/s) and very large user populations. Scaling requires both efficient attack detection algorithms as well as appropriate an execution environment. Our architecture considers the time budget of traffic data extraction and algorithmic processing, provides a suite of detection algorithms - each designed to present different and complementary views of the data-that generate many ¿traffic events,¿ and reduces false positives by correlating these traffic events into benign or malicious hypotheses.
W. Timothy Strayer, Walter C. Milliken, Ronald J. Watro, Walt Heimerdinger, Steven A. Harp, Robert P. Goldman, Dustin Spicuzza, Beverly Schwartz, David Mankins, Derrick Kong, Pieter Mudge Zatko
LCN1
2009 Detecting Botnets Using Command and Control Traffic
abstract
Botnets pose a significant threat to network-based applications and communications; it is believed that 16-25% of the computers connected to the Internet are members of a botnet. The detection of botnets is essential to prevent further damages. We approach this problem by monitoring the command and control (C2) communication traffic, as this reveals the botnet structure before any real harm is caused.We observe that C2 traffic exhibits a repeated pattern behavior. This is due to the nature of the pre-programmed behavior of bots. We explore this behavior and look for periodic components in C2 traffic. We use periodograms to study the periodic behavior, and apply Walker's large sample test to detect whether the traffic has a significant periodic component or not, and, if it does, then it is bot traffic. This test is independent of the structure and communication protocol used in the botnet, and does not require any a priori knowledge of a certain botnet behavior. Since we only look at the aggregate traffic behavior, it is also more scalable than other techniques that examine individual packets or track the communication flows of different hosts.We apply this test to two variants of botnet C2 communication traffic generated by SLINGbot, and show that the traffic in both variants exhibits periodic behavior. We compare the results we get on botnet C2 communication traffic to the ones we get on real traffic that is obtained from a secured enterprise network packet trace.
Basil AsSadhan, José M. F. Moura, David E. Lapsley, Christine E. Jones, W. Timothy Strayer
NCA5
2007 Efficient Multi-Dimensional Flow Correlation
abstract
Flow correlation algorithms compare flows to determine similarity, and are especially useful and well studied for detecting flow chains through "stepping stone" hosts. Most correlation algorithms use only one characteristic and require all values in the correlation matrix (the correlation value of all flows to all other flows) to be updated on every event. We have developed an algorithm that tracks multiple (n) characteristics per flow, and requires updating only the flow's n values upon an event, not all the values for all the flows. The n correlation values are used as coordinates for a point in n-space; two flows are considered correlated if there is a very small Euclidean distance between them. Our results show that this algorithm is efficient in space and compute time, is resilient against anomalies in the flow, and has uses outside of stepping stone detection.
W. Timothy Strayer, Christine E. Jones, Beverly Schwartz, Sarah Edwards, Walter C. Milliken, Alden W. Jackson
LCN1
2007 A Topological Analysis of Monitor Placement
abstract
The Internet is an extremely complex system, and it is essential that we be able to make accurate measurements in order to understand its underlying behavior or to detect improper behavior (e.g., attacks). The reality, however, is that it is impractical to fully instrument anything but relatively small networks and impossible to even partially instrument many parts of the Internet. This paper analyzes a subset of the general monitor placement problem where the goal is to maximize the coverage of the entire universe of potential communication pairs (i.e., source and destination are randomly distributed in the routable Internet address space). This issue arises, for example, when trying to detect/track a distributed attack. We present results from a simulation, seeded with data from skitter and RouteViews, that indicate we can monitor a packet with a high probability by monitoring relatively few points in the Internet. Our analysis suggests that the preferred strategy to place monitors should be to instrument one or two specific inter-AS links per AS for many ASes rather than deeply instrumenting a subset of the largest ASes.
Alden W. Jackson, Walter C. Milliken, Cesar A. Santivanez, Matthew Condell, W. Timothy Strayer
NCA5
2006 Using Machine Learning Techniques to Identify Botnet Traffic
abstract
To date, techniques to counter cyber-attacks have predominantly been reactive; they focus on monitoring network traffic, detecting anomalies and cyber-attack traffic patterns, and, a posteriori, combating the cyber-attacks and mitigating their effects. Contrary to such approaches, we advocate proactively detecting and identifying botnets prior to their being used as part of a cyber-attack (Strayer et al., 2006). In this paper, we present our work on using machine learning-based classification techniques to identify the command and control (C2) traffic of IRC-based botnets - compromised hosts that are collectively commanded using Internet relay chat (IRC). We split this task into two stages: (I) distinguishing between IRC and non-IRC traffic, and (II) distinguishing between botnet and real IRC traffic. For stage I, we compare the performance of J48, naive Bayes, and Bayesian network classifiers, identify the features that achieve good overall classification accuracy, and determine the classification sensitivity to the training set size. While sensitive to the training data and the attributes used to characterize communication flows, machine learning-based classifiers show promise in identifying IRC traffic. Using classification in stage II is trickier, since accurately labeling IRC traffic as botnet and non-botnet is challenging. We are currently exploring labeling flows as suspicious and non-suspicious based on telltales of hosts being compromised
Carl Livadas, Robert Walsh, David E. Lapsley, W. Timothy Strayer
LCN4
2006 Detecting Botnets with Tight Command and Control
abstract
Systems are attempting to detect botnets by examining traffic content for IRC commands or by setting up honeynets. Our approach for detecting botnets is to examine flow characteristics such as bandwidth, duration, and packet timing looking for evidence of botnet command and control activity. We have constructed an architecture that first eliminates traffic that is unlikely to be a part of a botnet, classifies the remaining traffic into a group that is likely to be part of a botnet, then correlates the likely traffic to find common communications patterns that would suggest the activity of a botnet. Our results show that botnet evidence can be extracted from a traffic trace containing almost 9 million flows
W. Timothy Strayer, Robert Walsh, Carl Livadas, David E. Lapsley
LCN1
2005 Architecture for Multi-Stage Network Attack Traceback
abstract
Attacks can originate from anywhere in the network but there is little the network can tell operators about where the attacker is located. Packet traceback techniques have been proposed to find the source of one or more IP packets, but some attackers use multiple remote login sessions, or stepping stones, to increase obfuscation. IP packet traceback can only find the source of one of the several connections in the stepping stone connection chain. Stealthy tracing attackers research light trace (STARLlTE) is a customization and significant extension to BBN's source path isolation engine (SPlE.) The goal of STARLlTE was to construct a prototype to integrate single packet traceback with stepping stone detection. The resulting prototype traces a packet to an ingress router, and then discovers if the flow of that packet is related to a flow in another connection. A successful correlation can then be continued until an ultimate source is located
W. Timothy Strayer, Christine E. Jones, Beverly Schwartz
LCN1
2004 Privacy issues in virtual private networks
W. Timothy Strayer
Comput. Commun.1
2003 Privacy Issues in an Insecure World
abstract
We all have a notion of privacy and understand that we trade some of it away in order to have normal social interactions and communal security. Networked computer systems are no different. The notion of privacy is running squarely against the need for security in an increasingly networked world. Is it possible to have secure systems that honor privacy? There are two basic ways to secure a network: prevent bad things from happening, and watch closely for bad things and prosecute those who commit them. Since our current preventative measures like authentication and authorization seem to be failing to adequately protect the network, we have turned more toward auditing and monitoring-first as a complement, and now increasingly as a substitute-for prevention. I discuss the impact security concerns is having on privacy, and suggest that today's trend of solving security by detecting intrusions through monitoring is a reaction to institutional paranoia as well as woefully inadequate software development processes. I argue that monitoring alone can't provide sufficient protection, and that in fact the trend of relying increasingly on intrusion detection systems tells us that we are really losing ground-not gaining-on providing computer security.
W. Timothy Strayer
NCA1
2002 Single-packet IP traceback
abstract
The design of the IP protocol makes it difficult to reliably identify the originator of an IP packet. Even in the absence of any deliberate attempt to disguise a packet's origin, widespread packet forwarding techniques such as NAT and encapsulation may obscure the packet's true source. Techniques have been developed to determine the source of large packet flows, but, to date, no system has been presented to track individual packets in an efficient, scalable fashion. We present a hash-based technique for IP traceback that generates audit trails for traffic within the network, and can trace the origin of a single IP packet delivered by the network in the recent past. We demonstrate that the system is effective, space efficient (requiring approximately 0.5% of the link capacity per unit time in storage), and implementable in current or next-generation routing hardware. We present both analytic and simulation results showing the system's effectiveness.
Alex C. Snoeren, Craig Partridge, Christine E. Jones, Fabrice Tchakountio, Beverly Schwartz, Stephen T. Kent, W. Timothy Strayer
IEEE/ACM Trans. Netw.8
2001 FIRE: flexible intra-AS routing environment
abstract
Current routing protocols are monolithic, specifying the algorithm used to construct forwarding tables, the metric used by the algorithm (generally some form of hop count), and the protocol used to distribute these metrics as an integrated package. The flexible intra-AS routing environment (FIRE) is a link-state, intradomain routing protocol that decouples these components. FIRE supports run-time-programmable algorithms and metrics over a secure link-state distribution protocol. By allowing the network operator to dynamically reprogram both the properties being advertised and the routing algorithms used to construct forwarding tables, FIRE enables the development and deployment of novel routing algorithms without the need for a new protocol to distribute state. FIRE supports multiple concurrent routing algorithms and metrics, each constructing separate forwarding tables. By using operator-specified packet filters, separate classes of traffic may be routed using completely different routing algorithms, all supported by a single routing protocol. This paper presents an overview of FIRE, focusing particularly on FIRE's novel aspects with respect to traditional routing protocols. We consider deploying several current unicast and multicast routing algorithms in FIRE, and describe our Java-based implementation.
Craig Partridge, Alex C. Snoeren, W. Timothy Strayer, Beverly Schwartz, Matthew Condell, Isidro Castiñeyra
IEEE J. Sel. Areas Commun.3
2000 FIRE: Flexible intra-AS routing environment
abstract
Current routing protocols are monolithic, specifying the algorithm used to construct forwarding tables, the metric used by the algorithm (generally some form of hop-count), and the protocol used to distribute these metrics as an integrated package. The Flexible Intra-AS Routing Environment (FIRE) is a link-state, intra-domain routing protocol that decouples these components. FIRE supports run-time-pro- grammable algorithms and metrics over a secure link-state distribution protocol. By allowing the network operator to dynamically reprogram both the information being advertised and the routing algorithm used to construct forwarding tables in Java, FIRE enables the development and deployment of novel routing algorithms without the need for a new protocol to distribute state. FIRE supports multiple concurrent routing algorithms and metrics, each constructing separate forwarding tables. By using operator-specified packet filters, separate classes of traffic are routed using completely different routing algorithms, all supported by a single routing protocol.
Craig Partridge, Alex C. Snoeren, W. Timothy Strayer, Beverly Schwartz, Matthew Condell, Isidro Castiñeyra
SIGCOMM3
2000 Smart packets: applying active networks to network management
abstract
This article introduces Smart Packets and describes the smart Packets architecture, the packet formats, the language and its design goals, and security considerations. Smart Packets is an Active Networks project focusing on applying active networks technology to network management and monitoring. Messages in active networks are programs that are executed at nodes on the path to one or more target hosts. Smart Packets programs are written in a tightly encoded, safe language specifically designed to support network management and avoid dangerous constructs and accesses. Smart Packets improves the management of large complex networks by (1) moving management decision points closer to the node being managed, (2) targeting specific aspects of the node for information rather than exhaustive collection via polling, and (3) abstracting the management concepts to language constructs, allowing nimble network control.
Beverly Schwartz, Alden W. Jackson, W. Timothy Strayer, Wenyi Zhou, R. Dennis Rockwell, Craig Partridge
ACM Trans. Comput. Syst.3
1996 Reliable Multicasting in the Xpress Transport Protocol
abstract
The Xpress transport protocol (XTP) is designed to meet the needs of distributed, real-time, and multimedia systems. This paper describes the genesis of recent improvements to XTP that provide mechanisms for reliable management of multicast groups, and gives details of the mechanisms used.
J. William Atwood, Octavian Catrina, John Fenton, W. Timothy Strayer
LCN4
1996 A Class-Chest for Deriving Transport Protocols
abstract
The development of new transport protocols or protocol algorithms suffers from the complexity of the environment in which they an intended to run. Modeling techniques attempt to avoid this by simulating the environment. Another approach to promoting rapid prototyping of protocols and protocol algorithms is to provide a pre-built infrastructure that is common to transport protocols, so that the focus is placed on the protocol-specific aspects. The Meta-Transport Library is a library of C++ base classes that implement or abstract out the mundane functions of a protocol; new protocol implementations are derived from the base classes. The result is a fully viable user-level transport protocol implementation, with emphasis on modularity. The collection of base classes form a "class-chest" of tools from which protocols can be developed and studied with as little change to a normal Unix environment as possible.
W. Timothy Strayer
LCN1
1996 Portable Run-Time Support for Dynamic Object-Oriented Parallel Processing
abstract
Mentat is an object-oriented parallel processing system designed to simplify the task of writing portable parallel programs for parallel machines and workstation networks. The Mentat compiler and run-time system work together to automatically manage the communication and synchronization between objects. The run-time system marshals member function arguments, schedules objects on processors, and dynamically constructs and executes large-grain data dependence graphs. In this article we present the Mentat run-time system. We focus on three aspects—the software architecture, including the interface to the compiler and the structure and interaction of the principle components of the run-time system; the run-time overhead on a component-by-component basis for two platforms, a Sun SparcStation 2 and an Intel Paragon; and an analysis of the minimum granularity required for application programs to overcome the run-time overhead.
Andrew S. Grimshaw, Jon B. Weissman, W. Timothy Strayer
ACM Trans. Comput. Syst.3
1993 A Parallel Object-Oriented Framework for Stencil Algorithms
abstract
The authors present an object-oriented framework for constructing parallel implementations of stencil algorithms. This framework simplifies the development process by encapsulating the common aspects of stencil algorithms in a base stencil class so that application-specific derived classes can be easily defined via inheritance and overloading. In addition, the stencil base class contains mechanisms for parallel execution. The result is a high-performance, parallel, application-specific stencil class. The authors present the design rationale for the base class and illustrate the derivation process by defining two subclasses, an image convolution class and a PDE solver. The classes have been implemented in Mentat, an object-oriented parallel programming system that is available on a variety of platforms. Performance results are given for a network of Sun SPARCstation IPCs.>
John F. Karpovich, Matthew Judd, W. Timothy Strayer, Andrew S. Grimshaw
HPDC3
1989 An argument for judicious use of error detection mechanisms in LANs
abstract
The authors examine the ISO Open Systems Interconnection philosophy and the error detection mechanisms at each layer. They trace the progress of a message through each of these layers and comment on the overhead of error detection. They also offer some performance results at the transport layer. They argue that the error detection rate in modern LANs is not improved by mechanisms above the MAC, but rather that performance is severely degraded.>
W. Timothy Strayer, Alfred C. Weaver
LCN1
1988 Performance measurements of Motorola's implementation of MAP
abstract
The authors present performance measurements for data transfer services at the CASE (common application service elements), transport, and datalink layers of Motorola's implementation of the Manufacturing Automation Protocol (MAP) for a range of message sizes. They compare the performance results of using a stop-and-wait vs. a sliding window protocol, and find that the sliding window permits a 40% speedup. The observe that end-to-end latency exceeds transmission delay by a factor of 25 for 1000-byte messages, thereby making all network access, transmission, and propagation delays negligible when compared to protocol processing. They show that the throughput of CASE and transport is basically linear with message size whereas the throughput of datalink is not. They identify the bottlenecks which constrain total system throughput at each layer.>
W. Timothy Strayer, Alfred C. Weaver
LCN1