6 ms·
I suppose the DoS you mentioned should be relatively easy to prevent. They don't have to cache all flows, just the most hot 20% which consume 80% of bandwidth.
by jsn 17y ago
I suppose the DoS you mentioned should be relatively easy to prevent. They don't have to cache all flows, just the most hot 20% which consume 80% of bandwidth. Probabilistic caching and/or ruthless pruning of cold flows can probably render the "exploding cache" attack impossible or at least impractical.
What bothers me more is routing table updates. I don't see how they can avoid invalidating the whole flow cache on each routing flap. OTOH, rebuilding the said top 20% of flows should be pretty fast, too.