<p>The paper deals with effective traffic filtration in DDoS prevention systems. One of the typical solutions is implementing mitigation filters on devices placed on the network border. In this study, we focus on switches and evaluate features of two main architectures. One uses specialized memory, Ternary Content Addressable Memory (TCAM), to store and process filters. The second utilizes standard Random Addressable Memory (RAM). While TCAM provides extremely low delay it is expensive. On the other hand, a RAM-based solution benefits from greater flexibility of filter format. Two exemplar medium-sized Juniper switches, namely QFX-5120 and QFX-10002, are tested for filter capacity. The experiment results revealed certain phenomena that may limit the applicability of these devices to mitigate massive attacks. To investigate Junos software intrinsic and test switch capacity deeper two basic filter aggregation strategies are proposed. The experiments performed allowed for identifying the maximum allowable number of filters for both tested switches and scenarios in which aggregation provides capacity gain.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Filter aggregation for DDoS prevention systems: hardware perspective

  • Piotr Arabas,
  • Marek Dawidiuk

摘要

The paper deals with effective traffic filtration in DDoS prevention systems. One of the typical solutions is implementing mitigation filters on devices placed on the network border. In this study, we focus on switches and evaluate features of two main architectures. One uses specialized memory, Ternary Content Addressable Memory (TCAM), to store and process filters. The second utilizes standard Random Addressable Memory (RAM). While TCAM provides extremely low delay it is expensive. On the other hand, a RAM-based solution benefits from greater flexibility of filter format. Two exemplar medium-sized Juniper switches, namely QFX-5120 and QFX-10002, are tested for filter capacity. The experiment results revealed certain phenomena that may limit the applicability of these devices to mitigate massive attacks. To investigate Junos software intrinsic and test switch capacity deeper two basic filter aggregation strategies are proposed. The experiments performed allowed for identifying the maximum allowable number of filters for both tested switches and scenarios in which aggregation provides capacity gain.