DeeP4R: Deep Packet Inspection in P4 using Packet Recirculation
Sahil Gupta, Devashish Gosain, Minseok Kwon, Hrishikesh B. Acharya
摘要
Software-defined networks are useful for multiple tasks, including firewalling, telemetry, and flow analysis. In particular, the P4 language makes it possible to carry out some simple packet processing tasks in the data plane, i.e., on the switch itself (without real-time support from the SDN controller or a server). However, owing to the limitations of packet parsing in P4, these tasks involve only the packet headers. In this paper, we present a novel approach that allows Deep Packet Inspection (DPI) – i.e., inspection of the packet payload – in the data plane, using P4 alone. We make use of the fact that in P4, a switch can clone and recirculate packets. One copy (clone) can be recirculated, slicing off a byte in each round, and using a finite-state machine to check if a target string has yet been seen. If the target string is found, the other copy (original packet) is discarded; if not, it is passed through. Our approach allows us to build the first application-layer firewall (URL filter) in the data plane, and to achieve essentially line-rate performance while filtering thousands of URLs, on a commodity programmable switch. It may in future also be used for other DPI tasks.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它它引用的顶会 Paper4
- NetHide: Secure and Practical Network Topology ObfuscationRoland Meier, Petar Tsankov, Vincent Lenders, Laurent Vanbever 等USENIX Security 2018 · 被引用 84 次
- Gallium: Automated Software Middlebox Offloading to Programmable SwitchesKaiyuan Zhang, Danyang Zhuo, Arvind KrishnamurthySIGCOMM 2020 · 被引用 50 次
- Programmable In-Network Security for Context-aware BYOD PoliciesQiao Kang, Lei Xue, Adam Morrison, Yuxin Tang 等USENIX Security 2020
- Poseidon: Mitigating Volumetric DDoS Attacks with Programmable SwitchesMenghao Zhang, Guanyu Li, Shicheng Wang, Chang Liu 等NDSS 2020
相关 Paper
- Sequence Abstractions for Flexible, Line-Rate Network MonitoringAndrew Johnson, Ryan Beckett, Xiaoqi Chen, Ratul Mahajan 等NSDI 2024 · 被引用 4 次
- Lucid: a language for control in the data planeJohn Sonchack, Devon Loehr, Jennifer Rexford, David WalkerSIGCOMM 2021 · 被引用 45 次
- P4Inv: Inferring Packet Invariants for Verification of Stateful P4 ProgramsDelong Zhang, Chong Ye, Fei HeINFOCOM 2024 · 被引用 3 次
- P4runpro: Enabling Runtime Programmability for RMT Programmable SwitchesYifan Yang, Lin He, Jiasheng Zhou, Xiaoyi Shi 等SIGCOMM 2024 · 被引用 12 次
- NetCL: A Unified Programming Framework for In-Network ComputingGeorge Karlos, Henri E. Bal, Lin WangSC 2024 · 被引用 3 次
