Lightweight Internet Bandwidth Allocation and Isolation with Fractional Fair Shares
Marc Wyss, Yih-Chun Hu, Vincent Lenders, Roland Meier, Adrian Perrig
摘要
Ensuring fair bandwidth allocations on the public Internet is challenging. Congestion control algorithms (CCAs) often fail in achieving fairness, especially when different CCAs operate simultaneously. This challenge becomes even more pronounced during volumetric distributed denial-of-service (DDoS) attacks, where legitimate traffic can be starved entirely. One approach to address this challenge is to enforce fairness by allocating bandwidth directly at routers. However, existing solutions generally fall into two categories: those that are easy to deploy but fail to provide secure in-network bandwidth isolation, and those that offer strong isolation guarantees but rely on complex assumptions that hinder real-world deployment. To bridge the gap between these two categories, we introduce a new fairness model based on the notion of a per-stream Fractional Fair Share (FFS). At each on-path node, a stream’s FFS, represented as packet labels and updated along the forwarding path, conveys its current fair share of egress bandwidth. The combination of a packet-carried FFS and probabilistic forwarding enables effective and scalable isolation of streams with minimal overhead. FFS is the first system to combine low implementation and deployment overhead with effective bandwidth isolation, while remaining robust against source address spoofing and volumetric DDoS attacks, and delivering high performance, scalability, as well as minimal latency and jitter. We show that FFS effectively isolates bandwidth across 15 different CCAs while keeping latency and jitter minimal. Our high-speed implementation sustains a 160 Gbps line rate on commodity hardware. Evaluated on realistic Internet topologies, FFS outperforms several of the most recent and secure bandwidth isolation systems in both median and total bandwidth allocation. In our security analysis, we prove that FFS guarantees a non-zero lower bound on bandwidth allocation for every traffic stream, ensuring that volumetric DDoS attacks, even when combined with source address spoofing, cannot prevent legitimate communication. Finally, we present an extension of FFS that provides accurate and secure rate feedback to the sender, allowing rapid rate adaptation with minimal packet loss.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper14
- Aggregate-based congestion control for pulse-wave DDoS defenseAlbert Gran Alcoz, Martin Strohmeier, Vincent Lenders, Laurent VanbeverSIGCOMM 2022 · 被引用 63 次
- Poseidon: Efficient, Robust, and Practical Datacenter CC via Deployable INTWeitao Wang, Masoud Moshref, Yuliang Li, Gautam Kumar 等NSDI 2023 · 被引用 58 次
- Twenty Years After: Hierarchical Core-Stateless Fair QueueingZhuolong Yu, Jingfeng Wu, Vladimir Braverman, Ion Stoica 等NSDI 2021 · 被引用 45 次
- Harmony: A Congestion-free Datacenter ArchitectureSaksham Agarwal, Qizhe Cai, Rachit Agarwal, David B. Shmoys 等NSDI 2024 · 被引用 19 次
- Towards provably performant congestion controlAnup Agarwal, Venkat Arun, Devdeep Ray, Ruben Martins 等NSDI 2024 · 被引用 17 次
相关 Paper
- Zero-setup Intermediate-rate Communication Guarantees in a Global InternetMarc Wyss, Adrian PerrigUSENIX Security 2024 · 被引用 3 次
- FRCC: Towards Provably Fair and Robust Congestion ControlAnup Agarwal, Venkat Arun, Srinivasan SeshanNSDI 2026
- Towards the Fairness of Traffic PolicerDanfeng Shan, Peng Zhang, Wanchun Jiang, Hao Li 等INFOCOM 2021 · 被引用 11 次
- Scalable Real-Time Bandwidth Fairness in SwitchesRobert MacDavid, Xiaoqi Chen, Jennifer RexfordINFOCOM 2023 · 被引用 15 次
- Managing Congestion Control Heterogeneity on the Internet with Approximate Performance IsolationAyush Mishra, Archit Bhatnagar, Yixuan Zhang, Ben Leong 等NSDI 2026
