Kabir, Kantola, and Llorente Santos
216
Most of the delay for establishing a new connection is attributed to the signalling
phase. So a new connection setup takes time, but a host that re‐utilizes an existing con‑
nection undergoes a lesser delay, since the connection state for establishing a data
connection already exists in the control and data planes. The only significant delay in
this case is for forwarding of the data packet. This is shown in Figure  9.7(b), which
splits the session setup into new connection establishment (e) and connection reuse (r).
To account for network uncertainties, the CES state machine can absorb any host
retransmissions while the CETP signalling is still converging.
9.4.1.1 Security Testing
We conducted a set of tests to evaluate CES security mechanisms. Table 9.2 presents the
result of security testing, which reveals effectiveness of the security mechanisms as well
as their penalty on CES performance in terms of processing delay.
In our testing, the spoofed addresses failed to place or claim a connection state, as
well as from leaking traffic into the CES served network, due to use of the signalling
over spoofing‐free underlying protocols such as TCP and TLS/TCP. CES uses the
proof‐of‐work mechanism to push the burden of communication towards the sender,
such that the sender spends more computing cycles than receiver. This de‐incentivises
CETP‐level floods from remote sources.
The CES authentication mechanism effectively identifies the remote CES node at the
cost of a minimal processing delay, using X.509 certificate and an optional signed CETP
header for validation. CES authentication is triggered on the first CETP flow from a new
source, and is carried together with other network level policies for achieving the trust.
Depending on the complexity of policies, there can be one or more round trips in
addition to the normal host‐to‐host policy negotiation, for the first CETP flow. As a
result, the first host‐to‐host level CETP flow establishes in approximately 300 msec for
2‐additional RTTs of the CES‐policy negotiation. Naturally, end‐to‐end link latency of
real network must be added to obtain the real first session setup delay. In case the con‑
nection setup takes longer than the host’s retransmission time, the oCES state machine
can absorb any host retransmissions while the CETP signalling is still converging.
The subsequent interactions re‐utilize this validation result, and thus host‐to‐host
signalling completes in 1 or 2 RTTs depending on the policies, in the duration
shown in Table 9.2. The authentication mechanism does not exhibit any false posi‑
tives or false negatives and hence safeguards CES against CETP‐level attacks from
unauthorized sources.
Table 9.2 CES Security testing.
KPIs and Processing delays
Testing results
CETP signalling roundtrips (RTT)
1‐RTT
2‐RTT
CETP Signalling delay (msec)
80 ms
145 ms
False negatives/positives (percentage)
None
Burden of proof‐of‐work mechanism
3 ms to Sender
0.001 ms for receiver
CES Authentication burden (on 1
st packet)
2 ms to sender
1.8 ms for receiver
Précédent

- 258/483

Suivant