Bedrock: Programmable Network Support for Secure RDMA Systems
Jiarong Xing, Kuo-Feng Hsu, Yiming Qiu, Ziyang Yang, Hongyi Liu, Ang Chen
摘要
Remote direct memory access (RDMA) has gained popularity in cloud datacenters. In RDMA, clients bypass server CPUs and directly read/write remote memory. Recent findings have highlighted a host of vulnerabilities with RDMA, which give rise to attacks such as packet injection, denial of service, and side channel leakage, but RDMA defenses are still lagging behind. As the RDMA datapath bypasses CPU-based software processing, traditional defenses cannot be easily inserted without incurring performance penalty. Bedrock develops a security foundation for RDMA inside the network, leveraging programmable data planes in modern network hardware. It designs a range of defense primitives, including source authentication, access control, as well as monitoring and logging, to address RDMA-based attacks. Bedrock does not incur software overhead to the critical datapath, and delivers native RDMA performance in data transfers. Moreover, Bedrock operates transparently to legacy RDMA systems, without requiring RNIC, OS, or RDMA library changes. We present a comprehensive set of experiments on Bedrock and demonstrate its effectiveness.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper17
- Empowering Azure Storage with RDMAWei Bai, Shanim Sainul Abdeen, Ankit Agrawal, Krishan Kumar Attre 等NSDI 2023 · 被引用 117 次
- Brain-on-Switch: Towards Advanced Intelligent Network Data Plane via NN-Driven Traffic Analysis at Line-SpeedJinzhu Yan, Haotian Xu, Zhuotao Liu, Qi Li 等NSDI 2024 · 被引用 60 次
- Reverie: Low Pass Filter-Based Switch Buffer Sharing for Datacenters with RDMA and TCP TrafficVamsi Addanki, Wei Bai, Stefan Schmid, Maria ApostolakiNSDI 2024 · 被引用 33 次
- A Scalable and Dynamic ACL System for In-Network DefenseChanghun Jung, Sian Kim, Rhongho Jang, David Mohaisen 等CCS 2022 · 被引用 17 次
- Cerberus: Enabling Efficient and Effective In-Network Monitoring on Programmable SwitchesHuancheng Zhou, Guofei GuS&P 2024 · 被引用 17 次
它引用的顶会 Paper14
- A large scale analysis of hundreds of in-memory cache clusters at TwitterJuncheng Yang, Yao Yue, K. V. RashmiOSDI 2020 · 被引用 245 次
- When Cloud Storage Meets RDMAYixiao Gao, Qiang Li, Lingbo Tang, Yongqing Xi 等NSDI 2021 · 被引用 228 次
- Ripple: A Programmable, Decentralized Link-Flooding Defense Against Adaptive AdversariesJiarong Xing, Wenqing Wu, Ang ChenUSENIX Security 2021 · 被引用 100 次
- Fast RDMA-based Ordered Key-Value Store using Remote Learned CacheXingda Wei, Rong Chen, Haibo ChenOSDI 2020 · 被引用 93 次
- NetHide: Secure and Practical Network Topology ObfuscationRoland Meier, Petar Tsankov, Vincent Lenders, Laurent Vanbever 等USENIX Security 2018 · 被引用 84 次
相关 Paper
- ReDMArk: Bypassing RDMA Security MechanismsBenjamin Rothenberger, Konstantin Taranov, Adrian Perrig, Torsten HoeflerUSENIX Security 2021 · 被引用 56 次
- sRDMA - Efficient NIC-based Authentication and Encryption for Remote Direct Memory AccessKonstantin Taranov, Benjamin Rothenberger, Adrian Perrig, Torsten HoeflerUSENIX ATC 2020 · 被引用 59 次
- Remote Direct Memory IntrospectionHongyi Liu, Jiarong Xing, Yibo Huang, Danyang Zhuo 等USENIX Security 2023
- Pythia: Remote Oracles for the MassesShin-Yeh Tsai, Mathias Payer, Yiying ZhangUSENIX Security 2019 · 被引用 37 次
- Ragnar: Exploring Volatile-Channel Vulnerabilities on RDMA NICYunpeng Xu, Yuchen Fan, Teng Ma, Shuwen DengDAC 2025 · 被引用 1 次
