• DocumentCode
    3170266
  • Title

    Source Address Filtering for Large Scale Network: A Cooperative Software Mechanism Design

  • Author

    Shu Yang ; Mingwei Xu ; Dan Wang ; Jianping Wu

  • Author_Institution
    Dept. of Comp Sci. & Tech., Tsinghua Univ., Beijing, China
  • fYear
    2012
  • fDate
    July 30 2012-Aug. 2 2012
  • Firstpage
    1
  • Lastpage
    7
  • Abstract
    Source address filtering is used as an important mechanism to prevent malicious traffic. Currently, most networks store filters in hardware such as TCAM, which has limited capacity, high power consumption and high cost. Although software can accommodate large number of filters, it needs multiple accesses to memory on the border router, which bears much more additional burden than other routers. In this paper, we propose a software-based mechanism for source address filtering. In our mechanism, we only need to check a few bits in source addresses on each router, rather than checking all bits on the ingress router. Through cooperation among routers, our mechanism ensures that malicious traffic will be filtered in the network. We formulate this problem as finding a cooperative scheme such that the loads on all routers are optimally balanced. We show that the problem can be optimally solved by dynamic programming. We evaluate our algorithms using comprehensive simulations with BRITE generated topologies and real world topologies. We conduct a case study on China Education and Research Network 2 (CERNET2) configurations, a large IPv6 network. Compared to checking 128-bit IP addresses on ingress routers, our algorithm checks at most 40 bits on each router.
  • Keywords
    IP networks; computer network security; dynamic programming; telecommunication computing; telecommunication network routing; telecommunication network topology; telecommunication traffic; BRITE generated topology; CERNET2 configuration; China Education and Research Network 2 configuration; IPv6 network; TCAM; border router; cooperative software mechanism design; dynamic programming; ingress router; large scale network; malicious traffic filtering; malicious traffic prevention; source address filtering; word length 128 bit; word length 40 bit; Heuristic algorithms; IP networks; Indexes; Network topology; Routing protocols; Topology; Vegetation;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Communications and Networks (ICCCN), 2012 21st International Conference on
  • Conference_Location
    Munich
  • Print_ISBN
    978-1-4673-1543-2
  • Type

    conf

  • DOI
    10.1109/ICCCN.2012.6289219
  • Filename
    6289219