Bad Packets Come Back, Worse Ones Don't
Petros Gigis, Mark James Handley, Stefano Vissicchio
Abstract
ISPs may notice that traffic from certain sources is entering their network at an unexpected location, but it is hard to know if this represents a problem or is just normal spoofed background noise. If such traffic is not spoofed, it would be useful to generate alerts, but alerting on background noise is not useful.
We describe Penny, a test ISPs can run to tell unspoofed traffic aggregates arriving on the wrong port from spoofed ones. The idea is simple: when receiving new traffic at unexpected routers, drop a few TCP packets. Non-spoofed TCP packets ("bad packets") will be retransmitted while spoofed ones ("worse packets") will not. However, building a robust test on top of this simple idea is subtle. We show how to deal with conflicting goals: minimizing performance degradation for legitimate flows, dealing with external conditions such as path changes and remote packet loss, and ensuring robustness against spoofers trying to evade our test.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on2
Related papers
- FAst in-network GraY failure detection for ISPsEdgar Costa Molero, Stefano Vissicchio, Laurent VanbeverSIGCOMM 2022 · 26 citations
- Deterrence of Intelligent DDoS via Multi-Hop Traffic DivergenceYuanjie Li, Hewu Li, Zhizheng Lv, Xingkun Yao et al.CCS 2021 · 11 citations
- SPIFFY: Inducing Cost-Detectability Tradeoffs for Persistent Link-Flooding AttacksMin Suk Kang, Virgil D. Gligor, Vyas SekarNDSS 2016 · 123 citations
- Deployment of Source Address Validation by Network Operators: A Randomized Control TrialQasim Lone, Alisa Frik, Matthew Luckie, Maciej Korczynski et al.S&P 2022 · 16 citations
- Website-Targeted False Content Injection by Network OperatorsGabi Nakibly, Jaime Schcolnik, Yossi RubinUSENIX Security 2016 · 28 citations
