Fan Yang, Ke Xu, Qi Li, Rongxing Lu, Bo Wu, T. Zhang, Yi Zhao, Meng Shen
{"title":"I Know If the Journey Changes: Flexible Source and Path Validation","authors":"Fan Yang, Ke Xu, Qi Li, Rongxing Lu, Bo Wu, T. Zhang, Yi Zhao, Meng Shen","doi":"10.1109/IWQoS49365.2020.9213001","DOIUrl":null,"url":null,"abstract":"No matter from the perspective of detection or defense, source and path validations are fundamentally primitive in constructing security mechanisms to greatly enhance network immunity in the face of malicious attacks, such as injection, traffic hijacking and hidden threats. However, existing works for source and path verification still impose a non-trivial operational overhead and lack adjustment capability for path dynamic changes. In this paper, we propose a flexible and convenient source and path validation protocol called PSVM, which uses an authentication structure PIC composed of ordered pieces to carry out packet verification. Specifically, in the basic PSVM protocol, PIC (related to cryptographic computation) in the packet header does not require any update during packet verification, which thus enables a lower processing overhead in routers. To cope with the challenge of path policy changes in the running protocol, the dynamic PSVM protocol supports controllable adjustment and migration, especially in the case of avoiding a malicious node or region. Our evaluation of a prototype experiment on Click demonstrates that the verification efficiency of PSVM is barely influenced by payload size or path length. Compared to the baseline of normal IP routing, the throughput reduction ratio of the basic PSVM is about 13%, which is much better than 28% of existing best solution Origin and Path Trace (OPT). In addition, for a 35-hop path with 30 pieces of PIC needed to be adjusted in dynamic PSVM, the throughput reduction ratio of routing cross node performing the adjustment operation after normal verification is only 2.4 %.","PeriodicalId":177899,"journal":{"name":"2020 IEEE/ACM 28th International Symposium on Quality of Service (IWQoS)","volume":"7 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-06-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"6","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2020 IEEE/ACM 28th International Symposium on Quality of Service (IWQoS)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/IWQoS49365.2020.9213001","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 6
Abstract
No matter from the perspective of detection or defense, source and path validations are fundamentally primitive in constructing security mechanisms to greatly enhance network immunity in the face of malicious attacks, such as injection, traffic hijacking and hidden threats. However, existing works for source and path verification still impose a non-trivial operational overhead and lack adjustment capability for path dynamic changes. In this paper, we propose a flexible and convenient source and path validation protocol called PSVM, which uses an authentication structure PIC composed of ordered pieces to carry out packet verification. Specifically, in the basic PSVM protocol, PIC (related to cryptographic computation) in the packet header does not require any update during packet verification, which thus enables a lower processing overhead in routers. To cope with the challenge of path policy changes in the running protocol, the dynamic PSVM protocol supports controllable adjustment and migration, especially in the case of avoiding a malicious node or region. Our evaluation of a prototype experiment on Click demonstrates that the verification efficiency of PSVM is barely influenced by payload size or path length. Compared to the baseline of normal IP routing, the throughput reduction ratio of the basic PSVM is about 13%, which is much better than 28% of existing best solution Origin and Path Trace (OPT). In addition, for a 35-hop path with 30 pieces of PIC needed to be adjusted in dynamic PSVM, the throughput reduction ratio of routing cross node performing the adjustment operation after normal verification is only 2.4 %.
无论从检测还是防御的角度来看,源验证和路径验证在构建安全机制时都是非常原始的,从而大大增强了网络在面对注入、流量劫持和隐藏威胁等恶意攻击时的免疫力。然而,现有的源和路径验证工作仍然施加了不小的操作开销,并且缺乏对路径动态变化的调整能力。本文提出了一种灵活方便的源路径验证协议PSVM,该协议使用由有序块组成的认证结构PIC进行数据包验证。具体来说,在基本的PSVM协议中,包头中的PIC(与加密计算相关)在包验证期间不需要任何更新,从而使路由器的处理开销更低。为了应对运行协议中路径策略变化的挑战,动态PSVM协议支持可控的调整和迁移,特别是在避免恶意节点或区域的情况下。我们在Click上对原型实验的评估表明,PSVM的验证效率几乎不受有效载荷大小或路径长度的影响。与普通IP路由基线相比,基本PSVM的吞吐量降低率约为13%,远远优于现有最佳解决方案Origin and Path Trace (OPT)的28%。此外,对于动态PSVM中需要调整的35跳、30条PIC的路径,正常验证后执行调整操作的路由交叉节点的吞吐量降低率仅为2.4%。