A Scalable and Dynamic ACL System for In-Network Defense
Changhun Jung, Sian Kim, Rhongho Jang, David Mohaisen, DaeHun Nyang
摘要
In-network/in-switch Access Control List (ACL) is an essential security component of modern networks. In high-speed networks, ACL rules are often placed in a switch's Ternary Content-Addressable Memory (TCAM) for timely ACL match-action and management (e.g., insertion and deletion). However, TCAM-based ACL systems are encountering an scalability issue owing to increasing demand on AI-powered autonomous defenses that detect and block attacks online, which inevitably derives finer-grained ACL rules. Existing solutions minimize the TCAM usage by partially offloading ACL matching into larger Static Random-Access Memory (SRAM) or customized hardware. Nevertheless, current SRAM-based solutions induce high management costs, especially a high rule-deployment latency, which delays time-sensitive defense actions. Also, the customized hardware approaches have its own scalability issue. To support autonomous defenses at a scale, in this paper, we propose an in-switch ACL system called PortCatcher, which breaks the trade-off between scalability and rule management latency. Systemwise, we detach layer-4 port matching from TCAM for improving its memory efficiency. Algorithm-wise, we introduce a novel port (range) rule representation concept, called linear range map (LRM), which enables port (range) matching in SRAM-based hash tables. LRM guarantees not only fast and scalable port matching but also low-latency ACL management for timely defenses. With static ACL datasets, we show that PortCatcher saves 74%∼90% TCAM space compared to state-of-the-art approaches by adding a small overhead to SRAM (0.49 SRAM entry per ACL rule). Also, we deploy Port-Catcher on a programmable switch to demonstrate that PortCatcher can serve the 5-tuple rule matching at a line rate, where port rules are completely matched in SRAM. With an attack traffic-driven dynamic ACL dataset, our use case study shows that PortCatcher's rule deployment is 168x faster than the state-of-the-art approach, allowing our in-network defense system to block 92.09% (55.45% more) malicious packets and all flows in an attack trace.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper6
- Enhancing Network Attack Detection with Distributed and In-Network Data Collection SystemSeyed Mohammad Mehdi Mirnajafizadeh, Ashwin Raam Sethuram, David Mohaisen, DaeHun Nyang 等USENIX Security 2024 · 被引用 12 次
- Scaling IP Lookup to Large Databases using the CRAM LensRobert Chang, Pradeep Dogga, Andy Fingerhut, Victor Rios 等NSDI 2025 · 被引用 4 次
- SketchFeature: High-Quality Per-Flow Feature Extractor Towards Security-Aware Data PlaneSian Kim, Seyed Mohammad Mehdi Mirnajafizadeh, Bara Kim, Rhongho Jang 等NDSS 2025
- Janus: Enabling Expressive and Efficient ACLs in High-speed RDMA CloudsZiteng Chen, Menghao Zhang, Jiahao Cao, Xuzheng Chen 等NDSS 2026
- A Robust Counting Sketch for Data Plane Intrusion DetectionSian Kim, Changhun Jung, RhongHo Jang, David Mohaisen 等NDSS 2023
它引用的顶会 Paper12
- Kitsune: An Ensemble of Autoencoders for Online Network Intrusion DetectionYisroel Mirsky, Tomer Doitshman, Yuval Elovici, Asaf ShabtaiNDSS 2018 · 被引用 945 次
- Jaqen: A High-Performance Switch-Native Approach for Detecting and Mitigating Volumetric DDoS Attacks with Programmable SwitchesZaoxing Liu, Hun Namkung, Georgios Nikolaidis, Jeongkeun Lee 等USENIX Security 2021 · 被引用 221 次
- Ripple: A Programmable, Decentralized Link-Flooding Defense Against Adaptive AdversariesJiarong Xing, Wenqing Wu, Ang ChenUSENIX Security 2021 · 被引用 100 次
- APKeep: Realtime Verification for Real NetworksPeng Zhang, Xu Liu, Hongkun Yang, Ning Kang 等NSDI 2020 · 被引用 99 次
- BeauCoup: Answering Many Network Traffic Queries, One Memory Update at a TimeXiaoqi Chen, Shir Landau Feibish, Mark Braverman, Jennifer RexfordSIGCOMM 2020 · 被引用 91 次
相关 Paper
- CATCAM: Constant-time Alteration Ternary CAM with Scalable In-Memory ArchitectureDibei Chen, Zhaoshi Li, Tianzhu Xiong, Zhiwei Liu 等MICRO 2020 · 被引用 6 次
- T-cache: Dependency-free Ternary Rule Cache for Policy-based ForwardingYing Wan, Haoyu Song, Yang Xu, Yilun Wang 等INFOCOM 2020 · 被引用 23 次
- HeatCache: A Heat-Predictive TCAM Rule Caching Framework with Dependency-Aware OptimizationLei Guo, Zeyu Luan, Qing Li, Zhuochen Fan 等INFOCOM 2026
- CAMPER: Exploring the Potential of Content Addressable Memory for 3D Point Cloud Efficient Range SearchJiapei Zheng, Lizhou Wu, Yutong Su, Jingyi Wang 等DAC 2024 · 被引用 1 次
- Efficient and Consistent TCAM UpdatesBohan Zhao, Rui Li, Jin Zhao, Tilman WolfINFOCOM 2020 · 被引用 21 次
