IP agnostic real-time traffic filtering and host identification using TCP timestamps

12Citations
Citations of this article
5Readers
Mendeley users who have this article in their library.

This article is free to access.

Abstract

In this work, we describe and evaluate the design and implementation of natfilterd, a flexible and lightweight extension of the Linux netfilter packet filter framework, which enables us to identify hosts completely independent of IP addresses by taking advantage of certain characteristics of TCP timestamps. As an immediate consequence, not only can we count hosts behind a NAT gateway but block TCP traffic from single hosts without blocking the gateway itself. Our work extends ideas from Bursztein, which we improve in terms of performance as well as matching quality and usability in practice. A theoretical runtime of O(log(n)) for matching packets against a database of n hosts is achieved. We empirically verify this result and conclude that our approach scales extremely well and is therefore suitable for at least medium-scale networks of a few thousand hosts. © 2013 IEEE.

Cite

CITATION STYLE

APA

Wicherski, G., Weingarten, F., & Meyer, U. (2013). IP agnostic real-time traffic filtering and host identification using TCP timestamps. In Proceedings - Conference on Local Computer Networks, LCN (pp. 647–654). IEEE Computer Society. https://doi.org/10.1109/LCN.2013.6761302

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free