Detecting ICMP Rate Limiting in the Internet

Detecting ICMP Rate Limiting in the Internet
复制标题

DOI:
10.1007/978-3-319-76481-8_1
复制
发表时间:
2018-03
期刊:
--
影响因子:
--
通讯作者:
Hang Guo;J. Heidemann
Hang Guo;J. Heidemann
中科院分区:
其他
文献类型:
--
作者:
Hang Guo;J. Heidemann

文献摘要

被引文献

相似文献

主动探测是许多网络测量的核心。如果未被检测到,则对VoIP流量的速率限制可能会扭曲测量结果并产生错误的结论。为了解决这个问题,我们系统地寻找在互联网上的码率限制。我们提出了一种新的算法FADER,它可以用最小的新测量流量从用户端跟踪中识别速率限制。我们验证了许多不同的网络配置的FADER在测试台实验的准确性,并表明它几乎总是检测到速率限制。有了这个信心,我们将我们的算法应用到整个互联网的随机样本,表明速率限制存在,但对于慢探测速率,速率限制是非常罕见的。对于我们随机抽取的40,493/24个区块(约占响应空间的2%),我们确认了6个区块(0.02%!)参见速率限制在每块0.39分组/秒。我们在公共数据集中查看了更高的速率,并建议当速率接近每/24块1个数据包/秒时,响应的下降与速率限制一致。我们还表明,即使是非常慢的探测(0.0001包/秒)可以遇到的NACK集中在一个单一的路由器附近的探测器的速率限制。
ICMP active probing is the center of many network measurements. Rate limiting to ICMP traffic, if undetected, could distort measurements and create false conclusions. To settle this concern, we look systematically for ICMP rate limiting in the Internet. We createFADER, a new algorithm that can identify rate limiting from user-side traces with minimal new measurement traffic. We validate the accuracy of FADER with many different network configurations in testbed experiments and show that it almost always detects rate limiting. With this confidence, we apply our algorithm to a random sample of the whole Internet, showing thatrate limiting existsbut thatfor slow probing rates, rate-limiting is very rare. For our random sample of 40,493 /24 blocks (about 2% of the responsive space), we confirm 6 blocks (0.02%!) see rate limiting at 0.39 packets/s per block. We look at higher rates in public datasets and suggest that fall-off in responses as rates approach 1 packet/s per /24 block is consistent with rate limiting. We also show that even very slow probing (0.0001 packet/s) can encounter rate limiting of NACKs that are concentrated at a single router near the prober.