| Path-quality monitoring in the presence of adversaries |
| Full text |
Pdf
(582 KB)
|
Source
|
Joint International Conference on Measurement and Modeling of Computer Systems
archive
Proceedings of the 2008 ACM SIGMETRICS international conference on Measurement and modeling of computer systems
table of contents
Annapolis, MD, USA
SESSION: Measurements
table of contents
Pages 193-204
Year of Publication: 2008
ISBN:978-1-60558-005-0
Also published in ...
|
|
Authors
|
|
Sharon Goldberg
|
Princeton University, Princeton, NJ, USA
|
|
David Xiao
|
Princeton University, Princeton, NJ, USA
|
|
Eran Tromer
|
MIT, Cambridge, MA, USA
|
|
Boaz Barak
|
Princeton University, Princeton, NJ, USA
|
|
Jennifer Rexford
|
Princeton University, Princeton, NJ, USA
|
|
| Sponsors |
|
| Publisher |
|
| Bibliometrics |
Downloads (6 Weeks): 20, Downloads (12 Months): 122, Citation Count: 4
|
|
|
ABSTRACT
Edge networks connected to the Internet need effective monitoring techniques to drive routing decisions and detect violations of Service Level Agreements (SLAs). However, existing measurement tools, like ping, traceroute, and trajectory sampling, are vulnerable to attacks that can make a path look better than it really is. In this paper, we design and analyze path-quality monitoring protocols that reliably raise an alarm when the packet-loss rate and delay exceed a threshold, even when an adversary tries to bias monitoring results by selectively delaying, dropping, modifying, injecting, or preferentially treating packets. Despite the strong threat model we consider in this paper, our protocols are efficient enough to run at line rate on high-speed routers. We present a secure sketching protocol for identifying when packet loss and delay degrade beyond a threshold. This protocol is extremely lightweight, requiring only 250-600 bytes of storage and periodic transmission of a comparably sized IP packet to monitor billions of packets. We also present secure sampling protocols that provide faster feedback and accurate round-trip delay estimates, at the expense of somewhat higher storage and communication costs. We prove that all our protocols satisfy a precise definition of secure path-quality monitoring and derive analytic expressions for the trade-off between statistical accuracy and system overhead. We also compare how our protocols perform in the client-server setting, when paths are asymmetric, and when packet marking is not permitted.
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
| |
1
|
Bad ISPs that cause trouble for BitTorrent clients. http://www.azureuswiki.com/index.php/Bad_ISPs.
|
| |
2
|
Keynote launches new SLA services, June 2001. http://investor.keynote.com/phoenix.zhtml?c=78522&p=irol-newsArticle_Print&ID=183745.
|
 |
3
|
|
 |
4
|
Noga Alon , Yossi Matias , Mario Szegedy, The space complexity of approximating the frequency moments, Proceedings of the twenty-eighth annual ACM symposium on Theory of computing, p.20-29, May 22-24, 1996, Philadelphia, Pennsylvania, United States
[doi> 10.1145/237814.237823]
|
| |
5
|
|
 |
6
|
Hitesh Ballani , Paul Francis , Xinyang Zhang, A study of prefix hijacking and interception in the internet, Proceedings of the 2007 conference on Applications, technologies, architectures, and protocols for computer communications, August 27-31, 2007, Kyoto, Japan
|
| |
7
|
B. Barak, S. Goldberg, and D. Xiao. Protocols and lower bounds for failure localization in the Internet. In IACR EUROCRYPT, 2008.
|
| |
8
|
J. L. Carter and M. N. Wegman. Universal classes of hash functions. JCSS, 18(2):143--154, 1979.
|
| |
9
|
|
| |
10
|
T. Dierks and E. Rescorla. The Transport Layer Security (TLS) Protocol Version 1.1. RFC 4346 (Proposed Standard), 2006.
|
 |
11
|
|
| |
12
|
|
| |
13
|
S. Goldberg and J. Rexford. Security vulnerabilities and solutions for packet sampling. IEEE Sarnoff Symposium, 2007.
|
| |
14
|
S. Goldberg, D. Xiao, E. Tromer, B. Barak, and J. Rexford. Path-quality monitoring in the presence of adversaries. Technical report, Princeton University Department of Computer Science, 2008.
|
| |
15
|
K. J. Houle and G. M. Weaver. Trends in denial of service attack technology. Technical report, CERT Coordination Center, 2001.
|
| |
16
|
IETF. Packet sampling working group. http://www.ietf.org/html.charters/psamp-charter.html.
|
| |
17
|
IETF. Working Group on IP Performance Metrics. http://www.ietf.org/html.charters/ippm-charter.html.
|
| |
18
|
|
 |
19
|
|
| |
20
|
W. Johnson and J. Lindenstrauss. Extensions of Lipshitz mapping into Hilbert space. Contemporary Mathematics, 26:189--206, 1984.
|
| |
21
|
M. Luckie, K. Cho, and B. Owens. Inferring and debugging path MTU discovery failures. In Internet Measurement Conference, 2005.
|
| |
22
|
D. Mills, A. Thyagarajan, and B. Huffman. Internet timekeeping around the globe. Proc. PTTI, pages 365--371, 1997.
|
 |
23
|
|
| |
24
|
|
| |
25
|
A. Nucci. Skype detection: Traffic classification in the dark, 2006. http://www.narus.com/_pdf/news/Converge-Skype%20Detection.pdf.
|
| |
26
|
|
 |
27
|
Joel Sommers , Paul Barford , Nick Duffield , Amos Ron, Improving accuracy in end-to-end packet loss measurement, Proceedings of the 2005 conference on Applications, technologies, architectures, and protocols for computer communications, August 22-26, 2005, Philadelphia, Pennsylvania, USA
|
 |
28
|
Joel Sommers , Paul Barford , Nick Duffield , Amos Ron, Accurate and efficient SLA compliance monitoring, Proceedings of the 2007 conference on Applications, technologies, architectures, and protocols for computer communications, August 27-31, 2007, Kyoto, Japan
|
 |
29
|
|
| |
30
|
Lakshminarayanan Subramanian , Volker Roth , Ion Stoica , Scott Shenker , Randy H. Katz, Listen and whisper: security mechanisms for BGP, Proceedings of the 1st conference on Symposium on Networked Systems Design and Implementation, p.10-10, March 29-31, 2004, San Francisco, California
|
| |
31
|
|
| |
32
|
J. Xu. Tutorial on network data streaming. In ACM SIGMETRICS, 2008.
|
CITED BY 4
|
|
|
|
|
|
|
|
Yaping Zhu , Rui Zhang-Shen , Sampath Rangarajan , Jennifer Rexford, Cabernet: connectivity architecture for better network services, Proceedings of the 2008 ACM CoNEXT Conference, p.1-6, December 09-12, 2008, Madrid, Spain
|
|
|
|
|