• DocumentCode
    63511
  • Title

    High-Performance Capabilities for 1-Hop Containment of Network Attacks

  • Author

    Wolf, Tilman ; Natarajan, Sriraam ; Vasudevan, Kamlesh T.

  • Author_Institution
    Dept. of Electr. & Comput. Eng., Univ. of Massachusetts, Amherst, MA, USA
  • Volume
    21
  • Issue
    6
  • fYear
    2013
  • fDate
    Dec. 2013
  • Firstpage
    1931
  • Lastpage
    1946
  • Abstract
    Capabilities-based networks present a fundamental shift in the security design of network architectures. Instead of permitting the transmission of packets from any source to any destination, routers deny forwarding by default. For a successful transmission, packets need to positively identify themselves and their permissions to the router. A major challenge for a high-performance implementation of such a network is an efficient design of the credentials that are carried in the packet and the verification procedure on the router. We present a capabilities system that uses packet credentials based on Bloom filters. The credentials are of fixed length (independent of the number of routers that are traversed by the packet) and can be verified by routers with a few simple operations. This high-performance design of capabilities makes it feasible that traffic is verified on every router in the network, and most attack traffic can be contained within a single hop. We present an analysis of our design and a practical protocol implementation that can effectively limit unauthorized traffic with only a small per-packet overhead.
  • Keywords
    Internet; computer network security; data structures; protocols; 1-hop containment; Internet; attack traffic; bloom filters; high-performance capabilities-based networks; network attacks; packet credentials; protocol implementation; security design; Computer architecture; Computer crime; Cryptography; Internet; Routing protocols; Bloom filter; data path processing; network security; off-by-default network;
  • fLanguage
    English
  • Journal_Title
    Networking, IEEE/ACM Transactions on
  • Publisher
    ieee
  • ISSN
    1063-6692
  • Type

    jour

  • DOI
    10.1109/TNET.2013.2240463
  • Filename
    6466406