arXiv · 2609.33308
Estimation is Not Enough: Carpet-Bombing Detection via Per-Packet Uniformity Testing
Abstract
Carpet-bombing attacks spread traffic uniformly across one or more destination IP prefixes, keeping every host in the prefix below alarm thresholds while exhausting prefix-level defenses. Existing carpet-bombing detectors run at seconds-to-minutes latency, too slow to respond within the attack window. Sketches support per-packet processing in fixed-width memory, a natural fit for cutting latency, yet no sketch-based detector exists for carpet bombing. Because source addresses can be spoofed, and attacks can be launched through reflection, source-side evidence is structurally unavailable and detection must anchor at the destination side. We present SweepSketch, the first sketch-based detection model for carpet bombing: it anchors at the destination, keeps no source state, and compresses a tagged self-cleaning T-HLL primitive, per-packet CUSUM decisions, and dual-EWMA change gates into 44-byte fixed-width buckets deployable on the Tofino2 programmable switch. Its design is supported by six theorems, including verifiable detection lower bounds. Under the same memory budget, SweepSketch leads all 10 baselines across the sketch, entropy, and sequential-testing classes in F1 (0.991). Its median alarm latency is 186--627 ms, and it has structural immunity to source spoofing. On 30 real/synthetic multi-prefix samples held out from parameter design, it detects all 140 victim prefixes.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Yutong Yan, Sijia Du, Haowei Wang, Bo Yang. 2026-09-27. Estimation is Not Enough: Carpet-Bombing Detection via Per-Packet Uniformity Testing. https://arxiv.org/abs/2609.33308
Cite the original work for its findings. Save a collection to share your selection of sources.