TY - JOUR
T1 - NetHCF
T2 - Filtering Spoofed IP Traffic With Programmable Switches
AU - Zhang, Menghao
AU - Li, Guanyu
AU - Kong, Xiao
AU - Liu, Chang
AU - Xu, Mingwei
AU - Gu, Guofei
AU - Wu, Jianping
N1 - Publisher Copyright:
© 2004-2012 IEEE.
PY - 2023/3/1
Y1 - 2023/3/1
N2 - In this paper, we identify the opportunity of using programmable switches to improve the state of the art in spoofed IP traffic filtering, and propose NetHCF, a line-rate in-network system to filter spoofed traffic. One key challenge in the design of NetHCF is to handle the restrictions stemmed from the limited computational model and memory resources of programmable switches. We address this by decomposing the HCF scheme into two complementary parts, by aggregating the IP-to-Hop-Count (IP2HC) mapping table for efficient memory usage, and by designing adaptive mechanisms to handle routing changes, IP popularity changes, and network activity dynamics. We implement an open-source prototype of NetHCF, and conduct extensive evaluations. The evaluation results demonstrate that NetHCF is able to process most legitimate traffic in 1 $\mu$μs, filter spoofed IP traffic effectively under network dynamics, with less than 30% of switch resource occupation.
AB - In this paper, we identify the opportunity of using programmable switches to improve the state of the art in spoofed IP traffic filtering, and propose NetHCF, a line-rate in-network system to filter spoofed traffic. One key challenge in the design of NetHCF is to handle the restrictions stemmed from the limited computational model and memory resources of programmable switches. We address this by decomposing the HCF scheme into two complementary parts, by aggregating the IP-to-Hop-Count (IP2HC) mapping table for efficient memory usage, and by designing adaptive mechanisms to handle routing changes, IP popularity changes, and network activity dynamics. We implement an open-source prototype of NetHCF, and conduct extensive evaluations. The evaluation results demonstrate that NetHCF is able to process most legitimate traffic in 1 $\mu$μs, filter spoofed IP traffic effectively under network dynamics, with less than 30% of switch resource occupation.
KW - Hop-count filtering
KW - programmable switches
KW - spoofed IP traffic
UR - https://www.scopus.com/pages/publications/85127059872
U2 - 10.1109/TDSC.2022.3161015
DO - 10.1109/TDSC.2022.3161015
M3 - 文章
AN - SCOPUS:85127059872
SN - 1545-5971
VL - 20
SP - 1641
EP - 1655
JO - IEEE Transactions on Dependable and Secure Computing
JF - IEEE Transactions on Dependable and Secure Computing
IS - 2
ER -