DocumentCode
3244549
Title
A Dynamic Stateful Multicast Firewall
Author
Shen Li ; Sivaraman, Vijay ; Krumm-Hellerl, A. ; Russell, Craig
Author_Institution
Univ. of New South Wales, Kensington
fYear
2007
fDate
24-28 June 2007
Firstpage
1280
Lastpage
1285
Abstract
Enterprises are faced with the challenge of enabling IP multicast applications without exposing their network to multicast denial-of-service attacks. Current practice is to use firewalls and manually configure them on a per-multicast-session basis. This imposes a high work-load on the network administrator, and severely reduces flexibility for end-users. In this paper, we propose and demonstrate a simple yet powerful multicast firewall algorithm that can, under most conditions, automatically distinguish unsolicited multicast packets and drop them to protect the network from denial-of-service attacks. Inspired by the "stateful" operation of unicast firewalls, our multicast firewall blocks unsolicited multicast packets by maintaining state information on multicast group membership and unicast interactions. We prototype our algorithm as a plug-in to Linux NetFilter, and present performance and scalability results from testing on a high-quality multicast video platform coupled with synthetic traffic from a network tester. Based on the prototype, we believe that it is feasible to build multicast firewalls that can, without manual intervention, and with minimal performance impact, protect the network against multicast attacks.
Keywords
computer networks; multicast communication; denial of service attacks; dynamic stateful; multicast firewall; multicast packets; unicast firewalls; Australia; Computer crime; Linux; Multicast algorithms; Multicast protocols; Protection; Prototypes; Routing; Testing; Unicast;
fLanguage
English
Publisher
ieee
Conference_Titel
Communications, 2007. ICC '07. IEEE International Conference on
Conference_Location
Glasgow
Print_ISBN
1-4244-0353-7
Type
conf
DOI
10.1109/ICC.2007.216
Filename
4288887
Link To Document