Detecting ICMP Rate Limiting in the Internet
Detecting ICMP Rate Limiting in the Internet
复制标题
DOI:
10.1007/978-3-319-76481-8_1
复制
发表时间:
2018-03
期刊:
影响因子:
--
通讯作者:
Hang Guo;J. Heidemann
中科院分区:
文献类型:
--
作者:
Hang Guo;J. Heidemann
ICMP active probing is the center of many network measurements. Rate limiting to ICMP traffic, if undetected, could distort measurements and create false conclusions. To settle this concern, we look systematically for ICMP rate limiting in the Internet. We createFADER, a new algorithm that can identify rate limiting from user-side traces with minimal new measurement traffic. We validate the accuracy of FADER with many different network configurations in testbed experiments and show that it almost always detects rate limiting. With this confidence, we apply our algorithm to a random sample of the whole Internet, showing thatrate limiting existsbut thatfor slow probing rates, rate-limiting is very rare. For our random sample of 40,493 /24 blocks (about 2% of the responsive space), we confirm 6 blocks (0.02%!) see rate limiting at 0.39 packets/s per block. We look at higher rates in public datasets and suggest that fall-off in responses as rates approach 1 packet/s per /24 block is consistent with rate limiting. We also show that even very slow probing (0.0001 packet/s) can encounter rate limiting of NACKs that are concentrated at a single router near the prober.