Загрузка...

Policy Injection: A Cloud Dataplane DoS Attack

This is a showcase/supplemental material to our SIGCOMM 2018 Demo (submission) entitled Policy Injection: A Cloud Dataplane DoS Attack.

The main insight in this demo is that in a cloud data plane where the hypervisor switch is implemented by an Open vSwitch, by specially crafted ACL rules and packet sequence it is possible to trash the megaflow cache resulting in a significant performance drop, and in certain cases, a full-blown Denial-of-Service can be "achieved".
The performances for the dst_port, dst_port+src_port, and dst_port+src_port+ip_src scenarios were dropped from the peak performance of 1.7M to 710K, 215K, and couple of hundreds PPS, respectively.

Видео Policy Injection: A Cloud Dataplane DoS Attack канала Levente Csikor
Яндекс.Метрика
Все заметки Новая заметка Страницу в заметки
Страницу в закладки Мои закладки
На информационно-развлекательном портале SALDA.WS применяются cookie-файлы. Нажимая кнопку Принять, вы подтверждаете свое согласие на их использование.
О CookiesНапомнить позжеПринять