首页> 外文会议>Stabilization, Safety, and Security of Distributed Systems >Our Brothers' Keepers: Secure Routing with High Performance
【24h】

Our Brothers' Keepers: Secure Routing with High Performance

机译:我们兄弟的守护者:高性能的安全路由

获取原文
获取原文并翻译 | 示例

摘要

The Trinity [1] spam classification system is based on a distributed hash table that is implemented using a structured peer-to-peer overlay. Such an overlay must be capable of processing hundreds of messages per second, and must be able to route messages to their destination even in the presence of failures and malicious peers that misroute packets or inject fraudulent routing information into the system. Typically there is tension between the requirements to route messages securely and efficiently in the overlay.rnWe describe a secure and efficient routing extension that we developed within the 13 [2] implementation of the Chord [3] overlay. Secure routing is accomplished through several complementary approaches: First, peers in close proximity form overlapping groups that police themselves to identify and mitigate fraudulent routing information. Second, a form of random routing solves the problem of entire packet flows passing through a malicious peer. Third, a message authentication mechanism links each message to it sender, preventing spoofing. Fourth, each peer's identifier links the peer to its network address, and at the same time uniformly distributes the peers in the key-space.rnLastly, we present our initial evaluation of the system, comprising a 255 peer overlay running on a local cluster. We describe our methodology and show that the overhead of our secure implementation is quite reasonable.
机译:Trinity [1]垃圾邮件分类系统基于使用结构化对等覆盖实现的分布式哈希表。这样的覆盖层必须能够每秒处理数百条消息,并且即使在出现故障以及错误地对数据包进行路由或将欺诈性路由信息注入系统的恶意对等设备的情况下,也必须能够将消息路由至其目的地。通常,在叠加层中安全有效地路由消息的要求之间存在紧张关系。rn我们描述了在Chord [3]叠加层的13 [2]实现中开发的安全有效的路由扩展。安全路由是通过几种互补的方法来实现的:首先,近距离的对等体形成重叠的组,这些组自行监管以识别和缓解欺诈性路由信息。其次,一种形式的随机路由解决了整个数据包流经过恶意对等点的问题。第三,消息认证机制将每个消息链接到它的发送者,以防止欺骗。第四,每个对等方的标识符将对等方链接到其网络地址,同时将对等方均匀地分布在密钥空间中。最后,我们介绍了对系统的初始评估,该系统包括在本地群集上运行的255个对等覆盖。我们描述了我们的方法,并表明我们安全实施的开销非常合理。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号