Filter aggregation for DDoS prevention systems: hardware perspective
摘要
The paper deals with effective traffic filtration in DDoS prevention systems. One of the typical solutions is implementing mitigation filters on devices placed on the network border. In this study, we focus on switches and evaluate features of two main architectures. One uses specialized memory, Ternary Content Addressable Memory (TCAM), to store and process filters. The second utilizes standard Random Addressable Memory (RAM). While TCAM provides extremely low delay it is expensive. On the other hand, a RAM-based solution benefits from greater flexibility of filter format. Two exemplar medium-sized Juniper switches, namely QFX-5120 and QFX-10002, are tested for filter capacity. The experiment results revealed certain phenomena that may limit the applicability of these devices to mitigate massive attacks. To investigate Junos software intrinsic and test switch capacity deeper two basic filter aggregation strategies are proposed. The experiments performed allowed for identifying the maximum allowable number of filters for both tested switches and scenarios in which aggregation provides capacity gain.