Title :
Optimal Filtering of Source Address Prefixes: Models and Algorithms
Author :
Soldo, Fabio ; Markopoulou, Athina ; Argyraki, Katerina
Author_Institution :
Univ. of California, Irvine, CA
Abstract :
How can we protect the network infrastructure from malicious traffic, such as scanning, malicious code propagation, and distributed denial-of-service (DDoS) attacks? One mechanism for blocking malicious traffic is filtering: access control lists (ACLs) can selectively block traffic based on fields of the IP header. Filters (ACLs) are already available in the routers today but are a scarce resource because they are stored in expensive ternary content addressable memory (TCAM). In this paper, we develop, for the first time, a framework for studying filter selection as a resource allocation problem. Within this framework, we study four practical cases of source address/prefix filtering, which correspond to different attack scenarios and operator´s policies. We show that filter selection optimization leads to novel variations of the multidimensional knapsack problem and we design optimal, yet computationally efficient, algorithms to solve them. We also evaluate our approach using data from Dshield.org and demonstrate that it brings significant benefits in practice. Our set of algorithms is a building block that can be immediately used by operators and manufacturers to block malicious traffic in a cost-efficient way.
Keywords :
IP networks; content-addressable storage; knapsack problems; resource allocation; security of data; telecommunication network routing; telecommunication security; telecommunication traffic; IP header; access control lists; distributed denial-of-service attacks; filter selection optimization; malicious code propagation attacks; malicious traffic; multidimensional knapsack problem; network infrastructure protection; optimal filtering; resource allocation problem; routers; scanning attacks; source address prefixes; ternary content addressable memory; Access control; Associative memory; Communication system traffic control; Computer crime; Design optimization; Filtering algorithms; Filters; Protection; Resource management; Traffic control;
Conference_Titel :
INFOCOM 2009, IEEE
Conference_Location :
Rio de Janeiro
Print_ISBN :
978-1-4244-3512-8
Electronic_ISBN :
0743-166X
DOI :
10.1109/INFCOM.2009.5062172