Paper Abstract and Keywords |
Presentation |
2018-03-02 15:00
Distributed High-Speed Packet Filtering System for Autonomous and Distributed Internet Security Infrastructure Hiroyuki Kimiyama, Yuya Kishi, Haruka Momo, Kaoru Sano, Naoki Yonezaki, Tomoaki Tsutsumi, Hirofumi Yamaki, Yoichiro Ueno, Ryoichi Sasaki, Hiroshi Kobayashi (Tokyo Denki Univ.) NS2017-237 |
Abstract |
(in Japanese) |
(See Japanese page) |
(in English) |
We proposed "Autonomous and distributed Internet security (AIS) infrastructure" that enables to
protect our resources on the Internet by cooperating with all ISPs since most of existing end-point protection solutions become unavailable to protect our resources from large scale attacks. This AIS infrastructure can discard attack packets by using Multi-Layer Binding Routers (MLBRs), placed at the nearest to actual origin of these attack packets, discard not only source IP address spoofed packets but also non-spoofed attack packets. However, MLBRs at border between an ISP introduced this infrastructure and an ISP not introduced it must discard large number of attack packets that have different attributions. Therefore, we should study how to implement filtering method for MLBRs to discard attack packets coming through over 100 Gbps line. In this paper, we propose a multi-layered and distributed packet filtering method to discard attack packets through 100 Gbps line, and we show that this proposed method enables to implement 100 Gbps filtering system by estimating retrieving performance. |
Keyword |
(in Japanese) |
(See Japanese page) |
(in English) |
Cyber attacks / DDoS attack / Distributed packet filter / High-speed packet filter / / / / |
Reference Info. |
IEICE Tech. Rep., vol. 117, no. 459, NS2017-237, pp. 391-396, March 2018. |
Paper # |
NS2017-237 |
Date of Issue |
2018-02-22 (NS) |
ISSN |
Print edition: ISSN 0913-5685 Online edition: ISSN 2432-6380 |
Copyright and reproduction |
All rights are reserved and no part of this publication may be reproduced or transmitted in any form or by any means, electronic or mechanical, including photocopy, recording, or any information storage and retrieval system, without permission in writing from the publisher. Notwithstanding, instructors are permitted to photocopy isolated articles for noncommercial classroom use without fee. (License No.: 10GA0019/12GB0052/13GB0056/17GB0034/18GB0034) |
Download PDF |
NS2017-237 |
|