Hashtray: Turning the tables on Scalable Client Classification

Nik Sultana, Pardis Pashakhanloo, Zihao Jin, A. Venkateswara Rao, Boon Thau Loo · Immunotechnology · 2019

Untrusted network clients can undergo a classification process before they are allowed to use more of a service’s resources, and services typically rely on a table to remember the clients’ classification. But as the number of clients increases so does the amount of state required to remember this classification over time.In this paper we explore the trade-off between data-structure accuracy and network size when needing to remember client state. We present Hashtray—a hash table library that consists of a generic API and instantiations of various kinds of tables—and a system to evaluate and compare different data structures.We evaluate Hashtray in the context of Denial-of-Service mitigation using both a modelled network of 106 machines, and a testbed experiment with over 200 hosts connecting to a version of Apache modified to use Hashtray. The system is open-sourced to enable others to extend or build on this work.

Read the paper · More papers on PaperTik