...
首页> 外文期刊>Networking, IEEE/ACM Transactions on >Optimal Source-Based Filtering of Malicious Traffic
【24h】

Optimal Source-Based Filtering of Malicious Traffic

机译:基于源的恶意流量最佳过滤

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

In this paper, we consider the problem of blocking malicious traffic on the Internet via source-based filtering. In particular, we consider filtering via access control lists (ACLs): These are already available at the routers today, but are a scarce resource because they are stored in the expensive ternary content addressable memory (TCAM). Aggregation (by filtering source prefixes instead of individual IP addresses) helps reduce the number of filters, but comes also at the cost of blocking legitimate traffic originating from the filtered prefixes. We show how to optimally choose which source prefixes to filter for a variety of realistic attack scenarios and operators' policies. In each scenario, we design optimal, yet computationally efficient, algorithms. Using logs from Dshield.org, we evaluate the algorithms and demonstrate that they bring significant benefit in practice.
机译:在本文中,我们考虑了通过基于源的筛选来阻止Internet上的恶意流量的问题。特别是,我们考虑通过访问控制列表(ACL)进行过滤:这些路由器已在当今的路由器上可用,但由于它们存储在昂贵的三态内容可寻址存储器(TCAM)中而成为稀缺资源。聚合(通过过滤源前缀而不是单个IP​​地址)有助于减少过滤器的数量,但同时也会以阻止源自已过滤前缀的合法流量为代价。我们将展示如何针对各种现实的攻击场景和运营商的策略,最佳选择要过滤的源前缀。在每种情况下,我们都设计最佳的,但计算效率高的算法。使用Dshield.org的日志,我们评估了算法并证明了它们在实践中带来了巨大的好处。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号