跳到主要导航 跳到搜索 跳到主要内容

NetHCF: Filtering Spoofed IP Traffic With Programmable Switches

  • Menghao Zhang
  • , Guanyu Li*
  • , Xiao Kong
  • , Chang Liu
  • , Mingwei Xu*
  • , Guofei Gu
  • , Jianping Wu
  • *此作品的通讯作者
  • Tsinghua University
  • Kuaishou
  • Texas A&M University

科研成果: 期刊稿件文章同行评审

摘要

In this paper, we identify the opportunity of using programmable switches to improve the state of the art in spoofed IP traffic filtering, and propose NetHCF, a line-rate in-network system to filter spoofed traffic. One key challenge in the design of NetHCF is to handle the restrictions stemmed from the limited computational model and memory resources of programmable switches. We address this by decomposing the HCF scheme into two complementary parts, by aggregating the IP-to-Hop-Count (IP2HC) mapping table for efficient memory usage, and by designing adaptive mechanisms to handle routing changes, IP popularity changes, and network activity dynamics. We implement an open-source prototype of NetHCF, and conduct extensive evaluations. The evaluation results demonstrate that NetHCF is able to process most legitimate traffic in 1 $\mu$μs, filter spoofed IP traffic effectively under network dynamics, with less than 30% of switch resource occupation.

源语言英语
页(从-至)1641-1655
页数15
期刊IEEE Transactions on Dependable and Secure Computing
20
2
DOI
出版状态已出版 - 1 3月 2023
已对外发布

指纹

探究 'NetHCF: Filtering Spoofed IP Traffic With Programmable Switches' 的科研主题。它们共同构成独一无二的指纹。

引用此