论文标题
基于ICMP速率限制的别名分辨率
Alias Resolution Based on ICMP Rate Limiting
论文作者
论文摘要
别名分辨率技术(例如MIDAR)合作,主要是通过主动测量,一组IP地址属于通用路由器。这些技术依赖于可以用作签名的不同路由器功能。它们的适用性受路由器的支持和签名的鲁棒性的影响。本文提出了一种称为Limited Ltd.的新别名分辨率工具,该工具利用了ICMP速率限制,该功能越来越多地由现代路由器支持,而现代路由器以前尚未用于别名分辨率。它将ICMP探针发送到目标界面以触发速率限制,从探针回复损失跟踪中提取功能。它使用机器学习分类器将成对的接口对为别名。我们描述了Limited Ltd.使用的算法的细节,并说明了其可行性和准确性。 Limited Ltd.不仅是第一个可以在IPv6路由器上执行别名分辨率的工具,该工具不会单明地增加碎片ID(例如杜松路由器),而且还可以补充IPV4别名别名分辨率的最新技术。我们的所有代码和收集的数据集均可公开使用。
Alias resolution techniques (e.g., Midar) associate, mostly through active measurement, a set of IP addresses as belonging to a common router. These techniques rely on distinct router features that can serve as a signature. Their applicability is affected by router support of the features and the robustness of the signature. This paper presents a new alias resolution tool called Limited Ltd. that exploits ICMP rate limiting, a feature that is increasingly supported by modern routers that has not previously been used for alias resolution. It sends ICMP probes toward target interfaces in order to trigger rate limiting, extracting features from the probe reply loss traces. It uses a machine learning classifier to designate pairs of interfaces as aliases. We describe the details of the algorithm used by Limited Ltd. and illustrate its feasibility and accuracy. Limited Ltd. not only is the first tool that can perform alias resolution on IPv6 routers that do not generate monotonically increasing fragmentation IDs (e.g., Juniper routers) but it also complements the state-of-the-art techniques for IPv4 alias resolution. All of our code and the collected dataset are publicly available.