Advanced search
Start date
Betweenand


In-situ Proof-of-Transit for Path-Aware Programmable Networks

Full text
Author(s):
Show less -
Borges, Everson Scherrer ; Bonella, Vitor Berger ; dos Santos, Abrado Jesus ; Menegueti, Gabriel Tetzner ; Dominicini, Cristina Klippel ; Martinello, Magnos ; Bernardos, CJ ; Martini, B ; Rojas, E ; Verdi, FL ; Zhu, Z ; Oki, E ; Parzyjegla, H
Total Authors: 13
Document type: Journal article
Source: 2023 IEEE 9TH INTERNATIONAL CONFERENCE ON NETWORK SOFTWARIZATION, NETSOFT; v. N/A, p. 8-pg., 2023-01-01.
Abstract

This paper presents a scalable and efficient solution for secure network design that involves the selection and verification of network paths. The proposed approach addresses the challenge of extending compliance policies to cover path-aware programmable networks by decoupling the routing/forwarding mechanisms from the Proof-of-Transit (PoT) implementation. Thus, two concepts are bounded: i) a source routing mechanism based on a fixed routeID representing a unique identifier per path, which serves as a key for the PoT lookup table; ii) the "in situ" that allows to collect telemetry information in the packet while the packet traverses a path. The former enables path selection with policy at the edge, while the later allows to perform path verification without extra probe-traffic. A P4 programmable language prototype demonstrates the effectiveness of this approach to protect against deviation attacks with low overhead. The results show a significant reduction in network's forwarding state for fat-tree topologies depending on the workload per path (flows/path). (AU)

FAPESP's process: 20/05182-3 - PORVIR-5G: programability, orchestration and virtualization in 5G networks
Grantee:José Marcos Silva Nogueira
Support Opportunities: Research Projects - Thematic Grants
FAPESP's process: 20/05174-0 - SAWI - Savvy Access through Worldwide Internet
Grantee:Epaminondas Aguiar de Sousa Junior
Support Opportunities: Research Grants - Innovative Research in Small Business - PIPE