Large-scale trading systems are a type of significant application for the stock exchange. Typically, these systems are deployed in datacenters to achieve a high throughput and minimal latencies. Given the advantages of decentralization and data security, these systems often prefer permissioned blockchains. However, there is still a large gap between the throughput of permissioned blockchains and traditional trading systems. To meet the performance demands of large-scale trading systems, many parallel permissioned blockchain frameworks are proposed. Among them, the shepherded parallel permissioned blockchain has the highest degree of parallelization. It parallelizes the stages of consensus and execution and utilizes the triangle inequality to ensure the high throughput of the system. In this paper, we reveal that the shepherded parallel permissioned blockchain is sensitive to network congestion, and congestion-related attacks can seriously harm the performance of the system. To tackle this dilemma, we introduce packet sending time as an innovative indicator for identifying malicious nodes. Leveraging this indicator, we propose Patronus, a malicious node detection and defense mechanism that effectively locates the malicious nodes and filters malicious packets on servers with eBPF programs. Testbed experiments show that Patronus can achieve a 29.9% throughput gain with low overheads.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Protecting Shepherded Parallel Permissioned Blockchain System from Congestion-Related Attack

  • Ziyang Zheng,
  • Qingkai Meng,
  • Tao Tong,
  • Shan Zhang,
  • Zhiyuan Wang,
  • Hongbin Luo

摘要

Large-scale trading systems are a type of significant application for the stock exchange. Typically, these systems are deployed in datacenters to achieve a high throughput and minimal latencies. Given the advantages of decentralization and data security, these systems often prefer permissioned blockchains. However, there is still a large gap between the throughput of permissioned blockchains and traditional trading systems. To meet the performance demands of large-scale trading systems, many parallel permissioned blockchain frameworks are proposed. Among them, the shepherded parallel permissioned blockchain has the highest degree of parallelization. It parallelizes the stages of consensus and execution and utilizes the triangle inequality to ensure the high throughput of the system. In this paper, we reveal that the shepherded parallel permissioned blockchain is sensitive to network congestion, and congestion-related attacks can seriously harm the performance of the system. To tackle this dilemma, we introduce packet sending time as an innovative indicator for identifying malicious nodes. Leveraging this indicator, we propose Patronus, a malicious node detection and defense mechanism that effectively locates the malicious nodes and filters malicious packets on servers with eBPF programs. Testbed experiments show that Patronus can achieve a 29.9% throughput gain with low overheads.