A Scalable and Dynamic ACL System for In-Network Defense
Changhun Jung, Sian Kim, Rhongho Jang, David Mohaisen, DaeHun Nyang
Abstract
In-network/in-switch Access Control List (ACL) is an essential security component of modern networks. In high-speed networks, ACL rules are often placed in a switch's Ternary Content-Addressable Memory (TCAM) for timely ACL match-action and management (e.g., insertion and deletion). However, TCAM-based ACL systems are encountering an scalability issue owing to increasing demand on AI-powered autonomous defenses that detect and block attacks online, which inevitably derives finer-grained ACL rules. Existing solutions minimize the TCAM usage by partially offloading ACL matching into larger Static Random-Access Memory (SRAM) or customized hardware. Nevertheless, current SRAM-based solutions induce high management costs, especially a high rule-deployment latency, which delays time-sensitive defense actions. Also, the customized hardware approaches have its own scalability issue. To support autonomous defenses at a scale, in this paper, we propose an in-switch ACL system called PortCatcher, which breaks the trade-off between scalability and rule management latency. Systemwise, we detach layer-4 port matching from TCAM for improving its memory efficiency. Algorithm-wise, we introduce a novel port (range) rule representation concept, called linear range map (LRM), which enables port (range) matching in SRAM-based hash tables. LRM guarantees not only fast and scalable port matching but also low-latency ACL management for timely defenses. With static ACL datasets, we show that PortCatcher saves 74%∼90% TCAM space compared to state-of-the-art approaches by adding a small overhead to SRAM (0.49 SRAM entry per ACL rule). Also, we deploy Port-Catcher on a programmable switch to demonstrate that PortCatcher can serve the 5-tuple rule matching at a line rate, where port rules are completely matched in SRAM. With an attack traffic-driven dynamic ACL dataset, our use case study shows that PortCatcher's rule deployment is 168x faster than the state-of-the-art approach, allowing our in-network defense system to block 92.09% (55.45% more) malicious packets and all flows in an attack trace.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers6
- Enhancing Network Attack Detection with Distributed and In-Network Data Collection SystemSeyed Mohammad Mehdi Mirnajafizadeh, Ashwin Raam Sethuram, David Mohaisen, DaeHun Nyang et al.USENIX Security 2024 · 12 citations
- Scaling IP Lookup to Large Databases using the CRAM LensRobert Chang, Pradeep Dogga, Andy Fingerhut, Victor Rios et al.NSDI 2025 · 4 citations
- SketchFeature: High-Quality Per-Flow Feature Extractor Towards Security-Aware Data PlaneSian Kim, Seyed Mohammad Mehdi Mirnajafizadeh, Bara Kim, Rhongho Jang et al.NDSS 2025
- Janus: Enabling Expressive and Efficient ACLs in High-speed RDMA CloudsZiteng Chen, Menghao Zhang, Jiahao Cao, Xuzheng Chen et al.NDSS 2026
- A Robust Counting Sketch for Data Plane Intrusion DetectionSian Kim, Changhun Jung, RhongHo Jang, David Mohaisen et al.NDSS 2023
Builds on12
- Kitsune: An Ensemble of Autoencoders for Online Network Intrusion DetectionYisroel Mirsky, Tomer Doitshman, Yuval Elovici, Asaf ShabtaiNDSS 2018 · 945 citations
- Jaqen: A High-Performance Switch-Native Approach for Detecting and Mitigating Volumetric DDoS Attacks with Programmable SwitchesZaoxing Liu, Hun Namkung, Georgios Nikolaidis, Jeongkeun Lee et al.USENIX Security 2021 · 221 citations
- Ripple: A Programmable, Decentralized Link-Flooding Defense Against Adaptive AdversariesJiarong Xing, Wenqing Wu, Ang ChenUSENIX Security 2021 · 100 citations
- APKeep: Realtime Verification for Real NetworksPeng Zhang, Xu Liu, Hongkun Yang, Ning Kang et al.NSDI 2020 · 99 citations
- BeauCoup: Answering Many Network Traffic Queries, One Memory Update at a TimeXiaoqi Chen, Shir Landau Feibish, Mark Braverman, Jennifer RexfordSIGCOMM 2020 · 91 citations
Related papers
- CATCAM: Constant-time Alteration Ternary CAM with Scalable In-Memory ArchitectureDibei Chen, Zhaoshi Li, Tianzhu Xiong, Zhiwei Liu et al.MICRO 2020 · 6 citations
- T-cache: Dependency-free Ternary Rule Cache for Policy-based ForwardingYing Wan, Haoyu Song, Yang Xu, Yilun Wang et al.INFOCOM 2020 · 23 citations
- HeatCache: A Heat-Predictive TCAM Rule Caching Framework with Dependency-Aware OptimizationLei Guo, Zeyu Luan, Qing Li, Zhuochen Fan et al.INFOCOM 2026
- CAMPER: Exploring the Potential of Content Addressable Memory for 3D Point Cloud Efficient Range SearchJiapei Zheng, Lizhou Wu, Yutong Su, Jingyi Wang et al.DAC 2024 · 1 citation
- Efficient and Consistent TCAM UpdatesBohan Zhao, Rui Li, Jin Zhao, Tilman WolfINFOCOM 2020 · 21 citations
