• Search Research Projects
  • Search Researchers
  • How to Use
  1. Back to previous page

Design of a Scalable Access Control List for DDoS Mitigation

Research Project

Project/Area Number 18K18043
Research Category

Grant-in-Aid for Early-Career Scientists

Allocation TypeMulti-year Fund
Review Section Basic Section 60060:Information network-related
Research InstitutionThe University of Tokyo

Principal Investigator

Kuga Yohei  東京大学, 情報基盤センター, 特任講師 (90816597)

Project Period (FY) 2018-04-01 – 2020-03-31
Project Status Completed (Fiscal Year 2019)
Budget Amount *help
¥3,900,000 (Direct Cost: ¥3,000,000、Indirect Cost: ¥900,000)
Fiscal Year 2019: ¥910,000 (Direct Cost: ¥700,000、Indirect Cost: ¥210,000)
Fiscal Year 2018: ¥2,990,000 (Direct Cost: ¥2,300,000、Indirect Cost: ¥690,000)
KeywordsDDoS緩和 / PCI Express / ネットワークハードウェア / インターコネクト / ACL / FPGA / ページテーブル / DDoS mitigation / Network security / Internet
Outline of Final Research Achievements

We researched a new mitigation method for DDoS attacks. The proposed method handles network traffic with hardware ACL filters on PCI Express (PCIe) devices, and the filter rules are stored on the host memory of the host PC connected with PCIe. In the method, the filter circuit operates the host memory by DMA. Thus, it enables high throughput DDoS mitigation with large memory space.
And we proposed a prototype environment for developing PCIe hardware by network programming. As this result, the proposed method has contributed to simplifying the research and development for network hardware.

Academic Significance and Societal Importance of the Research Achievements

パスワードの脆弱な監視カメラや家庭用ルータなどのIoT機器に感染するマルウェアの登場によって,IoTデバイスを用いたDDoS攻撃が大規模化している.本研究は,ソフトウェアによる柔軟なフィルタルールの記述と高スループット処理を両立したハードウェア型DDoS緩和を可能にし,インターネット運用の健全化に貢献する.

Report

(3 results)
  • 2019 Annual Research Report   Final Research Report ( PDF )
  • 2018 Research-status Report
  • Research Products

    (3 results)

All 2020 2019 2018

All Presentation (3 results) (of which Int'l Joint Research: 1 results)

  • [Presentation] NetTLP: A Development Platform for PCIe devices in Software Interacting with Hardware2020

    • Author(s)
      Yohei Kuga, Ryo Nakamura, Tahekshi Matsuya, Yuji Sekiya
    • Organizer
      17th USENIX Symposium on Networked Systems Design and Implementation (NSDI 20)
    • Related Report
      2019 Annual Research Report
    • Int'l Joint Research
  • [Presentation] 物理マシンと協調動作可能なソフトウェアによるPCIeデバイスエミュレーション手法2019

    • Author(s)
      空閑洋平, 松谷健史, 中村遼, 関谷勇司
    • Organizer
      並列/分散/協調処理に関するサマー・ワークショップ(SWoPP2019)
    • Related Report
      2019 Annual Research Report
  • [Presentation] DDoS緩和のための全IPv4空間を対象としたACLアーキテクチャの検討2018

    • Author(s)
      空閑洋平
    • Organizer
      電子情報通信学会 インターネットアーキテクチャ研究会
    • Related Report
      2018 Research-status Report

URL: 

Published: 2018-04-23   Modified: 2021-02-19  

Information User Guide FAQ News Terms of Use Attribution of KAKENHI

Powered by NII kakenhi