计算机科学
网络数据包
计算机网络
时间戳
默认网关
寄主(生物学)
块(置换群论)
吞吐量
匹配(统计)
互联网流量
鉴定(生物学)
互联网
分布式计算
操作系统
几何学
统计
生物
植物
数学
无线
生态学
作者
Georg Wicherski,Florian Weingarten,Ulrike Meyer
标识
DOI:10.1109/lcn.2013.6761302
摘要
In this work, we describe and evaluate the design and implementation of natfilterd, a flexible and lightweight extension of the Linux netfilter packet filter framework, which enables us to identify hosts completely independent of IP addresses by taking advantage of certain characteristics of TCP timestamps. As an immediate consequence, not only can we count hosts behind a NAT gateway but block TCP traffic from single hosts without blocking the gateway itself. Our work extends ideas from Bursztein, which we improve in terms of performance as well as matching quality and usability in practice. A theoretical runtime of O(log(n)) for matching packets against a database of n hosts is achieved. We empirically verify this result and conclude that our approach scales extremely well and is therefore suitable for at least medium-scale networks of a few thousand hosts.
科研通智能强力驱动
Strongly Powered by AbleSci AI