DocumentCode
63511
Title
High-Performance Capabilities for 1-Hop Containment of Network Attacks
Author
Wolf, Tilman ; Natarajan, Sriraam ; Vasudevan, Kamlesh T.
Author_Institution
Dept. of Electr. & Comput. Eng., Univ. of Massachusetts, Amherst, MA, USA
Volume
21
Issue
6
fYear
2013
fDate
Dec. 2013
Firstpage
1931
Lastpage
1946
Abstract
Capabilities-based networks present a fundamental shift in the security design of network architectures. Instead of permitting the transmission of packets from any source to any destination, routers deny forwarding by default. For a successful transmission, packets need to positively identify themselves and their permissions to the router. A major challenge for a high-performance implementation of such a network is an efficient design of the credentials that are carried in the packet and the verification procedure on the router. We present a capabilities system that uses packet credentials based on Bloom filters. The credentials are of fixed length (independent of the number of routers that are traversed by the packet) and can be verified by routers with a few simple operations. This high-performance design of capabilities makes it feasible that traffic is verified on every router in the network, and most attack traffic can be contained within a single hop. We present an analysis of our design and a practical protocol implementation that can effectively limit unauthorized traffic with only a small per-packet overhead.
Keywords
Internet; computer network security; data structures; protocols; 1-hop containment; Internet; attack traffic; bloom filters; high-performance capabilities-based networks; network attacks; packet credentials; protocol implementation; security design; Computer architecture; Computer crime; Cryptography; Internet; Routing protocols; Bloom filter; data path processing; network security; off-by-default network;
fLanguage
English
Journal_Title
Networking, IEEE/ACM Transactions on
Publisher
ieee
ISSN
1063-6692
Type
jour
DOI
10.1109/TNET.2013.2240463
Filename
6466406
Link To Document