NETHCF: Enabling Line-rate and Adaptive Spoofed IP Traffic Filtering

NETHCF: Enabling Line-rate and Adaptive Spoofed IP Traffic Filtering
复制标题

DOI:
10.1109/icnp.2019.8888057
复制
发表时间:
2019-10
期刊:
2019 IEEE 27th International Conference on Network Protocols (ICNP)
影响因子:
--
通讯作者:
G. Li;Menghao Zhang;Chang Liu;Xiao Kong;Ang Chen;G. Gu;Haixin Duan
G. Li;Menghao Zhang;Chang Liu;Xiao Kong;Ang Chen;G. Gu;Haixin Duan
中科院分区:
其他
文献类型:
--
作者:
G. Li;Menghao Zhang;Chang Liu;Xiao Kong;Ang Chen;G. Gu;Haixin Duan

文献摘要

被引文献

相似文献

在本文中,我们设计了一种用于过滤欺骗流量的线路速率内部系统源自可编程开关的计算模型和内存资源的限制。另一个用于控制平面。 。
In this paper, we design NETHCF, a line-rate in-network system for filtering spoofed traffic. NETHCF leverages the opportunity provided by programmable switches to design a novel defense against spoofed IP traffic, and it is highly efficient and adaptive. One key challenge stems from the restrictions of the computational model and memory resources of programmable switches. We address this by decomposing the HCF system into two complementary components—one component for the data plane and another for the control plane. We also aggregate the IP-to-Hop-Count (IP2HC) mapping table for efficient memory usage, and design adaptive mechanisms to handle end-to-end routing changes, IP popularity changes, and network activity dynamics. We have built a prototype on a hardware Tofino switch, and our evaluation demonstrates that NETHCF can achieve line-rate and adaptive traffic filtering with low overheads.