DocumentCode :
1911402
Title :
Optimal Filtering of Source Address Prefixes: Models and Algorithms
Author :
Soldo, Fabio ; Markopoulou, Athina ; Argyraki, Katerina
Author_Institution :
Univ. of California, Irvine, CA
fYear :
2009
fDate :
19-25 April 2009
Firstpage :
2446
Lastpage :
2454
Abstract :
How can we protect the network infrastructure from malicious traffic, such as scanning, malicious code propagation, and distributed denial-of-service (DDoS) attacks? One mechanism for blocking malicious traffic is filtering: access control lists (ACLs) can selectively block traffic based on fields of the IP header. Filters (ACLs) are already available in the routers today but are a scarce resource because they are stored in expensive ternary content addressable memory (TCAM). In this paper, we develop, for the first time, a framework for studying filter selection as a resource allocation problem. Within this framework, we study four practical cases of source address/prefix filtering, which correspond to different attack scenarios and operator´s policies. We show that filter selection optimization leads to novel variations of the multidimensional knapsack problem and we design optimal, yet computationally efficient, algorithms to solve them. We also evaluate our approach using data from Dshield.org and demonstrate that it brings significant benefits in practice. Our set of algorithms is a building block that can be immediately used by operators and manufacturers to block malicious traffic in a cost-efficient way.
Keywords :
IP networks; content-addressable storage; knapsack problems; resource allocation; security of data; telecommunication network routing; telecommunication security; telecommunication traffic; IP header; access control lists; distributed denial-of-service attacks; filter selection optimization; malicious code propagation attacks; malicious traffic; multidimensional knapsack problem; network infrastructure protection; optimal filtering; resource allocation problem; routers; scanning attacks; source address prefixes; ternary content addressable memory; Access control; Associative memory; Communication system traffic control; Computer crime; Design optimization; Filtering algorithms; Filters; Protection; Resource management; Traffic control;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
INFOCOM 2009, IEEE
Conference_Location :
Rio de Janeiro
ISSN :
0743-166X
Print_ISBN :
978-1-4244-3512-8
Electronic_ISBN :
0743-166X
Type :
conf
DOI :
10.1109/INFCOM.2009.5062172
Filename :
5062172
Link To Document :
بازگشت