Analyzing Traffic by Domain Name in the Data Plane

Analyzing Traffic by Domain Name in the Data Plane
复制标题

在数据平面中按域名分析流量

DOI:
10.1145/3482898.3483357
复制
发表时间:
2021
期刊:
Proceedings of the ACM SIGCOMM Symposium on SDN Research (SOSR)
影响因子:
--
通讯作者:
J. Rexford
J. Rexford
中科院分区:
--
文献类型:
--
作者:
Jason Kim;Hyojoon Kim;J. Rexford

文献摘要

被引文献

相似文献

将网络流量与人类可读的域名相关联,而不是像IP地址这样的低级标识符,有助于按域名测量流量、按域限制数据包速率以及识别物联网设备。然而,现有监控技术需要检查外部计算节点处的流量,从而引入开销和隐私风险。在本文中,我们介绍了Meta4,这是一个在数据平面上通过域名监控流量的框架,它从DNS响应消息中提取客户端IP、服务器IP和域名,并将域名与来自后续客户端-服务器会话的数据流量相关联。数据平面实现具有以下优点:以线速高效运行,使交换机能够对分组采取直接操作(例如,基于相关联的域对流量进行速率限制、阻止或标记),并保护用户信息的隐私。我们在Intel Tofino交换机上实施了Meta4,并根据来自运营网络的数据包跟踪对我们的原型进行了评估。
Associating network traffic with human-readable domain names, instead of low-level identifiers like IP addresses, is helpful for measuring traffic by domain name, rate-limiting packets by domain, and identifying IoT devices. However, existing monitoring techniques require examining traffic at an external compute node, introducing overhead and privacy risks. In this paper, we introduce Meta4, a framework for monitoring traffic by domain name in the data plane by extracting the client IP, server IP, and domain name from DNS response messages and associating the domain name with data traffic from the subsequent client-server session. A data-plane implementation has the benefits of running efficiently at line-rate, enabling the switch to take direct action on the packets (e.g., to rate-limit, block, or mark traffic based on the associated domain), and protecting the privacy of user information. We implemented Meta4 on an Intel Tofino switch and evaluated our prototype against packet traces from an operational network.