Attack Resilience of Cache Replacement Policies

Attack Resilience of Cache Replacement Policies
复制标题

DOI:
10.1109/infocom42981.2021.9488697
复制
发表时间:
2021-05
期刊:
IEEE INFOCOM 2021 - IEEE Conference on Computer Communications
影响因子:
--
通讯作者:
Tian Xie;Ting-nian He;P. Mcdaniel;Namitha Nambiar
Tian Xie;Ting-nian He;P. Mcdaniel;Namitha Nambiar
中科院分区:
其他
文献类型:
--
作者:
Tian Xie;Ting-nian He;P. Mcdaniel;Namitha Nambiar

文献摘要

被引文献

相似文献

缓存在计算机网络中广泛使用,通过重用以前的通信来加快访问速度,其中使用各种替换策略来管理缓存的内容。缓存的替换策略在其性能中起着关键作用,因此被广泛设计为在良性环境中实现高命中率。然而,一些研究表明,在良性环境中命中率较高的策略可能更容易受到拒绝服务攻击(DoS)的攻击,这些攻击会故意向不受欢迎的内容发送请求。为了理解这种攻击下的缓存性能,我们在TTL近似的框架下分析了一套有代表性的替换策略,看看它们在多大程度上保留了合法用户的命中率,同时考虑了缓存获取缺失内容的延迟。我们进一步开发了一种方案来适应缓存替换策略基于感知的攻击水平。我们对真实痕迹的分析和验证表明,尽管没有单一策略可以抵御所有攻击策略,但适当地调整替换策略可以显着提高缓存的攻击弹性。
Caches are pervasively used in computer networks to speed up access by reusing previous communications, where various replacement policies are used to manage the cached contents. The replacement policy of a cache plays a key role in its performance, and is thus extensively engineered to achieve a high hit ratio in benign environments. However, some studies showed that a policy with a higher hit ratio in benign environments may be more vulnerable to denial of service (DoS) attacks that intentionally send requests for unpopular contents. To understand the cache performance under such attacks, we analyze a suite of representative replacement policies under the framework of TTL approximation in how well they preserve the hit ratios for legitimate users, while incorporating the delay for the cache to obtain a missing content. We further develop a scheme to adapt the cache replacement policy based on the perceived level of attack. Our analysis and validation on real traces show that although no single policy is resilient to all the attack strategies, suitably adapting the replacement policy can notably improve the attack resilience of the cache.