English

CLEF: Limiting the Damage Caused by Large Flows in the Internet Core (Technical Report)

Networking and Internet Architecture 2018-07-17 v1

Abstract

The detection of network flows that send excessive amounts of traffic is of increasing importance to enforce QoS and to counter DDoS attacks. Large-flow detection has been previously explored, but the proposed approaches can be used on high-capacity core routers only at the cost of significantly reduced accuracy, due to their otherwise too high memory and processing overhead. We propose CLEF, a new large-flow detection scheme with low memory requirements, which maintains high accuracy under the strict conditions of high-capacity core routers. We compare our scheme with previous proposals through extensive theoretical analysis, and with an evaluation based on worst-case-scenario attack traffic. We show that CLEF outperforms previously proposed systems in settings with limited memory.

Keywords

Cite

@article{arxiv.1807.05652,
  title  = {CLEF: Limiting the Damage Caused by Large Flows in the Internet Core (Technical Report)},
  author = {Hao Wu and Hsu-Chun Hsiao and Daniele E. Asoni and Simon Scherrer and Adrian Perrig and Yih-Chun Hu},
  journal= {arXiv preprint arXiv:1807.05652},
  year   = {2018}
}

Comments

45 pages, 17th International Conference on Cryptology And Network Security (CANS 2018)

R2 v1 2026-06-23T03:02:08.223Z