Loading web-font TeX/Math/Italic
NetHCF: Filtering Spoofed IP Traffic With Programmable Switches | IEEE Journals & Magazine | IEEE Xplore

NetHCF: Filtering Spoofed IP Traffic With Programmable Switches


Abstract:

In this paper, we identify the opportunity of using programmable switches to improve the state of the art in spoofed IP traffic filtering, and propose NetHCF, a line-rate...Show More

Abstract:

In this paper, we identify the opportunity of using programmable switches to improve the state of the art in spoofed IP traffic filtering, and propose NetHCF, a line-rate in-network system to filter spoofed traffic. One key challenge in the design of NetHCF is to handle the restrictions stemmed from the limited computational model and memory resources of programmable switches. We address this by decomposing the HCF scheme into two complementary parts, by aggregating the IP-to-Hop-Count (IP2HC) mapping table for efficient memory usage, and by designing adaptive mechanisms to handle routing changes, IP popularity changes, and network activity dynamics. We implement an open-source prototype of NetHCF, and conduct extensive evaluations. The evaluation results demonstrate that NetHCF is able to process most legitimate traffic in 1 \mus, filter spoofed IP traffic effectively under network dynamics, with less than 30% of switch resource occupation.
Published in: IEEE Transactions on Dependable and Secure Computing ( Volume: 20, Issue: 2, 01 March-April 2023)
Page(s): 1641 - 1655
Date of Publication: 22 March 2022

ISSN Information:

Funding Agency:


Contact IEEE to Subscribe

References

References is not available for this document.