...
首页> 外文期刊>Computer Communications >Source address filtering for large scale networks
【24h】

Source address filtering for large scale networks

机译:大型网络的源地址过滤

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

Source address filtering is very important for protecting networks from malicious traffic. Most networks use hardware-based solutions such as TCAM-based filtering, however, they suffer from limited capacity, high power consumption and high monetary cost. Although software, such as SRAM, is larger, cheaper and consumes less power, the software-based solutions need multiple accesses in memory, which as a result bear much more additional lookup burden. In this paper, we propose a new software-based mechanism. In our mechanism, routers cooperate with each other, and each only checks a few bits rather than all bits in source addresses. Our mechanism can guarantee the correctness, i.e., filtering all malicious traffic. We formulate it as an optimization problem where the loads across the network can be optimally balanced. We solve the problem by dynamic programming. With the increasing number of filters, storage could also become a bottleneck for source address filtering. Our mechanism improves this by distributing filters among different routers. We re-formulate the problem by adding an additional storage constraint. Then we prove that the problem is NP-Complete, and propose a heuristic algorithm to solve it. At last, using comprehensive simulations with various topologies, we show that the mechanism greatly improves both lookup burden and storage space. We conduct a case study on China Education and Research Network 2 (CERNET2), the largest pure-IPv6 network in the world. Using CERNET2 configurations, we show that our algorithm checks less than 40 bits on each router, compared with 128 bits in IPv6 addresses.
机译:源地址过滤对于保护网络免遭恶意流量非常重要。大多数网络使用基于硬件的解决方案,例如基于TCAM的过滤,但是,它们存在容量受限,功耗高和货币成本高的问题。尽管诸如SRAM之类的软件更大,更便宜并且消耗的功率更少,但是基于软件的解决方案需要在内存中进行多次访问,因此将承担更多的额外查找负担。在本文中,我们提出了一种基于软件的新机制。在我们的机制中,路由器相互配合,并且每个路由器仅检查源地址中的几位而不是所有位。我们的机制可以保证正确性,即过滤所有恶意流量。我们将其表述为一个优化问题,可以优化网络中的负载。我们通过动态编程解决了这个问题。随着过滤器数量的增加,存储也可能成为源地址过滤的瓶颈。我们的机制通过在不同路由器之间分配过滤器来改善这一点。我们通过添加其他存储约束来重新制定问题。然后我们证明问题是NP完全的,并提出了启发式算法来解决。最后,使用具有各种拓扑的综合仿真,我们证明了该机制极大地改善了查找负担和存储空间。我们对中国教育研究网络2(CERNET2)(世界上最大的纯IPv6网络)进行了案例研究。使用CERNET2配置,我们证明了我们的算法检查每个路由器上少于40位,而IPv6地址中只有128位。

著录项

  • 来源
    《Computer Communications》 |2014年第1期|64-76|共13页
  • 作者单位

    Department of Computer Science and Technology, Tsinghua University, Beijing, China,Tsinghua National Laboratory for Information Science and Technology, Beijing, China;

    Department of Computer Science and Technology, Tsinghua University, Beijing, China,Tsinghua National Laboratory for Information Science and Technology, Beijing, China,Room 9-402, East Main Building, Tsinghua University, 100084 Beijing, China;

    Department of Computing, The Hong Kong Polytechnic University, Hung Horn, KL, Hong Kong;

    Department of Computer Science and Technology, Tsinghua University, Beijing, China,Tsinghua National Laboratory for Information Science and Technology, Beijing, China;

    Department of Computer Science and Technology, Tsinghua University, Beijing, China,Tsinghua National Laboratory for Information Science and Technology, Beijing, China;

  • 收录信息 美国《科学引文索引》(SCI);美国《工程索引》(EI);
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Source address filtering; Distributed filtering; Network security;

    机译:源地址过滤;分布式过滤网络安全;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号