Repository logo

Infoscience

  • English
  • French
Log In
Logo EPFL, École polytechnique fédérale de Lausanne

Infoscience

  • English
  • French
Log In
  1. Home
  2. Academic and Research Output
  3. Journal articles
  4. Optinal Source-Based Filtering of Malicious Traffic
 
research article

Optinal Source-Based Filtering of Malicious Traffic

Soldo, Fabio
•
Argyraki, Katerina  
•
Markopoulou, Athina
2012
IEEE ACM Transactions on Networking

In this paper, we consider the problem of blocking malicious traffic on the Internet via source-based filtering. In particular, we consider filtering via access control lists (ACLs): These are already available at the routers today, but are a scarce resource because they are stored in the expensive ternary content addressable memory (TCAM). Aggregation (by filtering source prefixes instead of individual IP addresses) helps reduce the number of filters, but comes also at the cost of blocking legitimate traffic originating from the filtered prefixes. We show how to optimally choose which source prefixes to filter for a variety of realistic attack scenarios and operators' policies. In each scenario, we design optimal, yet computationally efficient, algorithms. Using logs from Dshield.org, we evaluate the algorithms and demonstrate that they bring significant benefit in practice.

  • Details
  • Metrics
Type
research article
DOI
10.1109/TNET.2011.2161615
Web of Science ID

WOS:000303068300005

Author(s)
Soldo, Fabio
Argyraki, Katerina  
Markopoulou, Athina
Date Issued

2012

Published in
IEEE ACM Transactions on Networking
Volume

20

Issue

2

Start page

381

End page

395

Subjects

Traffic filtering

•

Denial-of-service attacks

•

Clustering algorithms

Editorial or Peer reviewed

REVIEWED

Written at

OTHER

EPFL units
NAL  
Available on Infoscience
May 11, 2012
Use this identifier to reference this record
https://infoscience.epfl.ch/handle/20.500.14299/80294
Logo EPFL, École polytechnique fédérale de Lausanne
  • Contact
  • infoscience@epfl.ch

  • Follow us on Facebook
  • Follow us on Instagram
  • Follow us on LinkedIn
  • Follow us on X
  • Follow us on Youtube
AccessibilityLegal noticePrivacy policyCookie settingsEnd User AgreementGet helpFeedback

Infoscience is a service managed and provided by the Library and IT Services of EPFL. © EPFL, tous droits réservés