DocumentCode :
3007813
Title :
Fast Algorithms for Heavy Distinct Hitters using Associative Memories
Author :
Bandi, Nagender ; Agrawal, Divyakant ; El Abbadi, Amr
Author_Institution :
Dept. of Comput. Sci., Univ. of California, Santa Barbara, CA
fYear :
2007
fDate :
25-27 June 2007
Firstpage :
6
Lastpage :
6
Abstract :
Real-time detection of worm attacks, port scans and distributed denial of service (DDoS) attacks, as network packets belonging to these security attacks flow through a network router, is of paramount importance. In a typical worm attack, a worm infected host tries to spread the worm by scanning a number of other hosts thus resulting in significant number of network connections at an intermediate router. Detecting such attacks amounts to finding all hosts that are associated with unusually high number of other hosts, which is equivalent to solving the classic heavy distinct hitter problem over data streams. While several heavy distinct hitter solutions have been proposed and evaluated in a standard CPU setting, most of the above applications typically execute on special networking architectures called network processing units (NPUs). These NPUs interface with special associative memories known as the ternary content addressable memories (TCAMs) to provide gigabit rate forwarding at network routers. In this paper, we describe how the integrated architecture of NPU and TCAMs can be exploited to develop high-speed solutions for heavy distinct hitters.
Keywords :
content-addressable storage; invasive software; telecommunication network routing; telecommunication security; associative memory; attack detection; data streams; distributed denial of service attack; heavy distinct hitter; network packet; network processing unit; network router; security attack; ternary content addressable memory; worm attack; Associative memory; Central Processing Unit; Computer crime; Computer science; Computer security; Computer worms; Data security; Hardware; Sampling methods; Stock markets;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Distributed Computing Systems, 2007. ICDCS '07. 27th International Conference on
Conference_Location :
Toronto, ON
ISSN :
1063-6927
Print_ISBN :
0-7695-2837-3
Electronic_ISBN :
1063-6927
Type :
conf
DOI :
10.1109/ICDCS.2007.110
Filename :
4268163
Link To Document :
بازگشت