TY - JOUR
T1 - Axarpsc
T2 - Scalable arp snooping using policy-based mirroring of core switches with arp log contraction
AU - Ohmori, Motoyuki
AU - Miyata, Naoki
AU - Okamura, Koji
N1 - Publisher Copyright:
© 2021 Information Processing Society of Japan.
PY - 2021
Y1 - 2021
N2 - In order to handle a computer security incident or network failure, it is important to grasp a list of pairs of IP and MAC addresses of the hosts. A traditional method based upon ARP table polling, however, has two major drawbacks that 1) some pairs of IP and MAC addresses may not be obtained and 2) it incurs a heavy load on a core switch. In order to overcome these drawbacks, this paper proposes AXARPSC that is the novel scalable ARP snooping to build a list of pairs of IP and MAC addresses. AXARPSC can avoid missing pairs of IP and MAC addresses by monitoring all ARP traffic. AXARPSC also can reduce a CPU load on a recent high-end core switch by approximately 20%. AXARPSC is scalable because AXARPSC incurs no additional CPU load even though the number of hosts increases. AXARPSC employs a policy-based mirroring of a switch that mirrors traffic that matches a specified filter. The policy-based mirroring can mirror ARP traffic only, and reduce the load on an ARP parsing server. AXARPSC can also contract multiple contiguous ARP messages that have the same pair of an IP address and MAC address, as if one ARP message is observed.
AB - In order to handle a computer security incident or network failure, it is important to grasp a list of pairs of IP and MAC addresses of the hosts. A traditional method based upon ARP table polling, however, has two major drawbacks that 1) some pairs of IP and MAC addresses may not be obtained and 2) it incurs a heavy load on a core switch. In order to overcome these drawbacks, this paper proposes AXARPSC that is the novel scalable ARP snooping to build a list of pairs of IP and MAC addresses. AXARPSC can avoid missing pairs of IP and MAC addresses by monitoring all ARP traffic. AXARPSC also can reduce a CPU load on a recent high-end core switch by approximately 20%. AXARPSC is scalable because AXARPSC incurs no additional CPU load even though the number of hosts increases. AXARPSC employs a policy-based mirroring of a switch that mirrors traffic that matches a specified filter. The policy-based mirroring can mirror ARP traffic only, and reduce the load on an ARP parsing server. AXARPSC can also contract multiple contiguous ARP messages that have the same pair of an IP address and MAC address, as if one ARP message is observed.
UR - http://www.scopus.com/inward/record.url?scp=85103625600&partnerID=8YFLogxK
UR - http://www.scopus.com/inward/citedby.url?scp=85103625600&partnerID=8YFLogxK
U2 - 10.2197/IPSJJIP.29.198
DO - 10.2197/IPSJJIP.29.198
M3 - Article
AN - SCOPUS:85103625600
SN - 0387-5806
VL - 29
SP - 198
EP - 204
JO - Journal of information processing
JF - Journal of information processing
ER -