论文标题
通过天桥预订保护关键的域间通信
Protecting Critical Inter-Domain Communication through Flyover Reservations
论文作者
论文摘要
为了防止互联网中自然发生或不利引起的拥塞,我们提出了天桥预订的概念,这是一种从根本上解决问题的新方法,用于满足关键低容量应用程序的可用性需求。与基于路径的预订系统相反,天桥对单个自主系统级别上的细粒度“基于HOP”的带宽保留。我们通过大图上的模拟通过模拟来证明这种方法的可伸缩性。此外,我们介绍了Helia,这是一种用于安全的天桥预订设置和数据传输的协议。我们根据DPDK的实现来评估Helia的性能,证明了160 Gbps的预订流量的身份验证和转发。我们的安全分析表明,Helia可以抵抗预订入场和交通转发的各种强大攻击。尽管它很简单,但Helia在许多关键指标中的表现都超过了当前的最新预订系统。
To protect against naturally occurring or adversely induced congestion in the Internet, we propose the concept of flyover reservations, a fundamentally new approach for addressing the availability demands of critical low-volume applications. In contrast to path-based reservation systems, flyovers are fine-grained "hop-based" bandwidth reservations on the level of individual autonomous systems. We demonstrate the scalability of this approach experimentally through simulations on large graphs. Moreover, we introduce Helia, a protocol for secure flyover reservation setup and data transmission. We evaluate Helia's performance based on an implementation in DPDK, demonstrating authentication and forwarding of reservation traffic at 160 Gbps. Our security analysis shows that Helia can resist a large variety of powerful attacks against reservation admission and traffic forwarding. Despite its simplicity, Helia outperforms current state-of-the-art reservation systems in many key metrics.