{"id":{"repo_id":"texas","oai_identifier":"oai:repositories.lib.utexas.edu:2152/652"},"canonical_url":"https://search.dev.ndltd.org/etd/texas/oai:repositories.lib.utexas.edu:2152/652","repository":{"repo_id":"texas","name":"University of Texas","base_url":"https://repositories.lib.utexas.edu/server/oai/request"},"display":{"title":"Hop integrity: a defense against denial-of-service attacks","abstract":"A computer network is said to provide hop integrity iff the following three conditions hold for every pair of adjacent routers p and q in the network. First, p does not forward any message to q if q has not been up and reachable. Second, when q receives a message m supposedly from p, then q can check that m was not modified after it was sent. Third, when q receives a message m supposedly from p, then q can check that m was not a replay of an old message sent by p. In this dissertation, we propose three protocols that can be added to the routers in a computer network so that the network can provide hop integrity, and thus overcome most denial-of-service attacks. These three protocols are the secure address resolution protocol, the weak hop integrity protocol, and the strong hop integrity protocol. The secure address resolution protocol includes an inviteaccept protocol and a request-reply protocol, and requires a secure server connected to the Ethernet. The weak hop integrity protocol includes a secret exchange protocol and an integrity check protocol. The strong hop integrity protocol combines a soft sequence number protocol with the weak hop integrity protocol. We also present an alternative way to achieve strong hop integrity with hard sequence numbers. All the protocols are stateless, require small overhead, and do not constrain the network protocol in the routers in any way.","abstract_html":"A computer network is said to provide hop integrity iff the following three conditions hold for every pair of adjacent routers p and q in the network. First, p does not forward any message to q if q has not been up and reachable. Second, when q receives a message m supposedly from p, then q can check that m was not modified after it was sent. Third, when q receives a message m supposedly from p, then q can check that m was not a replay of an old message sent by p. In this dissertation, we propose three protocols that can be added to the routers in a computer network so that the network can provide hop integrity, and thus overcome most denial-of-service attacks. These three protocols are the secure address resolution protocol, the weak hop integrity protocol, and the strong hop integrity protocol. The secure address resolution protocol includes an inviteaccept protocol and a request-reply protocol, and requires a secure server connected to the Ethernet. The weak hop integrity protocol includes a secret exchange protocol and an integrity check protocol. The strong hop integrity protocol combines a soft sequence number protocol with the weak hop integrity protocol. We also present an alternative way to achieve strong hop integrity with hard sequence numbers. All the protocols are stateless, require small overhead, and do not constrain the network protocol in the routers in any way.","abstract_has_math":false,"creators":["Huang, Chin-Tser"],"institution":"The University of Texas at Austin","degree_name":"Doctor of Philosophy","degree_level":"Doctoral","degree_discipline":"Computer Sciences","degree_department":null,"school":null,"contributors":[],"advisors":["Gouda, Mohamed G., 1947-"],"committee_chairs":[],"committee_members":[],"year":2003,"date_issued":"2003","date_published":"2003","updated_at":"2026-07-24T05:01:06Z","subjects":[],"languages":["eng"],"rights":["Copyright is held by the author. Presentation of this material on the Libraries&apos; web site by University Libraries, The University of Texas at Austin was made possible under a limited license grant from the author who has retained all copyrights in the works."],"rights_urls":[],"identifier_entries":[{"key":"dc:identifier","label":"Identifier","values":["b56832424"],"render_values":[{"text":"b56832424","href":null,"code":true}]}]},"links":{"outbound_url":"http://hdl.handle.net/2152/652","outbound_label":"Handle","outbound_source":"dc:identifier.uri"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor.advisor","label":"Advisor","values":["Gouda, Mohamed G., 1947-"]},{"key":"dc:creator","label":"Author","values":["Huang, Chin-Tser"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date.accessioned","label":"Dc Date Accessioned","values":["2008-08-28T21:30:18Z"]},{"key":"dc:date.available","label":"Dc Date Available","values":["2008-08-28T21:30:18Z"]},{"key":"dc:date.issued","label":"Date","values":["2003"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Computer Sciences"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Doctoral"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Doctor of Philosophy"]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["The University of Texas at Austin"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language.iso","label":"Language (ISO)","values":["eng"]},{"key":"dc:rights","label":"Dc Rights","values":["Copyright is held by the author. Presentation of this material on the Libraries&apos; web site by University Libraries, The University of Texas at Austin was made possible under a limited license grant from the author who has retained all copyrights in the works."]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["b56832424"]},{"key":"dc:identifier.uri","label":"Identifier URI","values":["http://hdl.handle.net/2152/652"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["text"]},{"key":"dc:description.abstract","label":"Abstract","values":["A computer network is said to provide hop integrity iff the following three conditions hold for every pair of adjacent routers p and q in the network. First, p does not forward any message to q if q has not been up and reachable. Second, when q receives a message m supposedly from p, then q can check that m was not modified after it was sent. Third, when q receives a message m supposedly from p, then q can check that m was not a replay of an old message sent by p. In this dissertation, we propose three protocols that can be added to the routers in a computer network so that the network can provide hop integrity, and thus overcome most denial-of-service attacks. These three protocols are the secure address resolution protocol, the weak hop integrity protocol, and the strong hop integrity protocol. The secure address resolution protocol includes an inviteaccept protocol and a request-reply protocol, and requires a secure server connected to the Ethernet. The weak hop integrity protocol includes a secret exchange protocol and an integrity check protocol. The strong hop integrity protocol combines a soft sequence number protocol with the weak hop integrity protocol. We also present an alternative way to achieve strong hop integrity with hard sequence numbers. All the protocols are stateless, require small overhead, and do not constrain the network protocol in the routers in any way."]},{"key":"dc:format.medium","label":"Dc Format Medium","values":["electronic"]},{"key":"dc:title","label":"Title","values":["Hop integrity: a defense against denial-of-service attacks"]}]}],"canonical_facts":{"dc:contributor.advisor":["Gouda, Mohamed G., 1947-"],"dc:creator":["Huang, Chin-Tser"],"dc:date.accessioned":["2008-08-28T21:30:18Z"],"dc:date.available":["2008-08-28T21:30:18Z"],"dc:date.issued":["2003"],"dc:description":["text"],"dc:description.abstract":["A computer network is said to provide hop integrity iff the following three conditions hold for every pair of adjacent routers p and q in the network. First, p does not forward any message to q if q has not been up and reachable. Second, when q receives a message m supposedly from p, then q can check that m was not modified after it was sent. Third, when q receives a message m supposedly from p, then q can check that m was not a replay of an old message sent by p. In this dissertation, we propose three protocols that can be added to the routers in a computer network so that the network can provide hop integrity, and thus overcome most denial-of-service attacks. These three protocols are the secure address resolution protocol, the weak hop integrity protocol, and the strong hop integrity protocol. The secure address resolution protocol includes an inviteaccept protocol and a request-reply protocol, and requires a secure server connected to the Ethernet. The weak hop integrity protocol includes a secret exchange protocol and an integrity check protocol. The strong hop integrity protocol combines a soft sequence number protocol with the weak hop integrity protocol. We also present an alternative way to achieve strong hop integrity with hard sequence numbers. All the protocols are stateless, require small overhead, and do not constrain the network protocol in the routers in any way."],"dc:format.medium":["electronic"],"dc:identifier":["b56832424"],"dc:identifier.uri":["http://hdl.handle.net/2152/652"],"dc:language.iso":["eng"],"dc:rights":["Copyright is held by the author. Presentation of this material on the Libraries&apos; web site by University Libraries, The University of Texas at Austin was made possible under a limited license grant from the author who has retained all copyrights in the works."],"dc:title":["Hop integrity: a defense against denial-of-service attacks"],"thesis:degree_discipline":["Computer Sciences"],"thesis:degree_level":["Doctoral"],"thesis:degree_name":["Doctor of Philosophy"],"thesis:institution_name":["The University of Texas at Austin"]},"updated_at":"2026-07-24T05:01:06Z"}