...
首页> 外文期刊>Networking, IEEE/ACM Transactions on >Optimal Source-Based Filtering of Malicious Traffic
【24h】

Optimal Source-Based Filtering of Malicious Traffic

机译:基于最佳源的恶意流量过滤

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

In this paper, we consider the problem of blocking malicious traffic on the Internet via source-based filtering. In particular, we consider filtering via access control lists (ACLs): These are already available at the routers today, but are a scarce resource because they are stored in the expensive ternary content addressable memory (TCAM). Aggregation (by filtering source prefixes instead of individual IP addresses) helps reduce the number of filters, but comes also at the cost of blocking legitimate traffic originating from the filtered prefixes. We show how to optimally choose which source prefixes to filter for a variety of realistic attack scenarios and operators' policies. In each scenario, we design optimal, yet computationally efficient, algorithms. Using logs from Dshield.org, we evaluate the algorithms and demonstrate that they bring significant benefit in practice.
机译:在本文中,我们考虑通过基于源的过滤阻止互联网上的恶意流量的问题。特别是,我们考虑通过访问控制列表(ACL)进行过滤:这些在今天的路由器上已经可用,但是稀缺资源,因为它们存储在昂贵的三元内容可寻址存储器(TCAM)中。聚合(通过过滤源前缀而不是单个IP​​地址)有助于减少过滤器的数量,但也以阻止源自过滤前缀的合法流量的成本。我们展示了如何最佳选择过滤哪些源前缀,以获取各种现实攻击方案和运营商的策略。在每个场景中,我们设计最佳,但计算地高效,算法。使用来自DShield.org的日志,我们评估算法并证明它们在实践中带来了重大好处。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号