DocumentCode
1911402
Title
Optimal Filtering of Source Address Prefixes: Models and Algorithms
Author
Soldo, Fabio ; Markopoulou, Athina ; Argyraki, Katerina
Author_Institution
Univ. of California, Irvine, CA
fYear
2009
fDate
19-25 April 2009
Firstpage
2446
Lastpage
2454
Abstract
How can we protect the network infrastructure from malicious traffic, such as scanning, malicious code propagation, and distributed denial-of-service (DDoS) attacks? One mechanism for blocking malicious traffic is filtering: access control lists (ACLs) can selectively block traffic based on fields of the IP header. Filters (ACLs) are already available in the routers today but are a scarce resource because they are stored in expensive ternary content addressable memory (TCAM). In this paper, we develop, for the first time, a framework for studying filter selection as a resource allocation problem. Within this framework, we study four practical cases of source address/prefix filtering, which correspond to different attack scenarios and operator´s policies. We show that filter selection optimization leads to novel variations of the multidimensional knapsack problem and we design optimal, yet computationally efficient, algorithms to solve them. We also evaluate our approach using data from Dshield.org and demonstrate that it brings significant benefits in practice. Our set of algorithms is a building block that can be immediately used by operators and manufacturers to block malicious traffic in a cost-efficient way.
Keywords
IP networks; content-addressable storage; knapsack problems; resource allocation; security of data; telecommunication network routing; telecommunication security; telecommunication traffic; IP header; access control lists; distributed denial-of-service attacks; filter selection optimization; malicious code propagation attacks; malicious traffic; multidimensional knapsack problem; network infrastructure protection; optimal filtering; resource allocation problem; routers; scanning attacks; source address prefixes; ternary content addressable memory; Access control; Associative memory; Communication system traffic control; Computer crime; Design optimization; Filtering algorithms; Filters; Protection; Resource management; Traffic control;
fLanguage
English
Publisher
ieee
Conference_Titel
INFOCOM 2009, IEEE
Conference_Location
Rio de Janeiro
ISSN
0743-166X
Print_ISBN
978-1-4244-3512-8
Electronic_ISBN
0743-166X
Type
conf
DOI
10.1109/INFCOM.2009.5062172
Filename
5062172
Link To Document