• Home
  • Search
  • Analyzing Traffic by Domain Name in the Data Plane
  • Open Access IconOpen Access
  • Cite Icon34
  • https://doi.org/10.1145/3482898.3483357Copy DOI Icon

Analyzing Traffic by Domain Name in the Data Plane

  • Oct 11, 2021
  • Jason Kim +2 more
Show More
  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

Associating network traffic with human-readable domain names, instead of low-level identifiers like IP addresses, is helpful for measuring traffic by domain name, rate-limiting packets by domain, and identifying IoT devices. However, existing monitoring techniques require examining traffic at an external compute node, introducing overhead and privacy risks. In this paper, we introduce Meta4, a framework for monitoring traffic by domain name in the data plane by extracting the client IP, server IP, and domain name from DNS response messages and associating the domain name with data traffic from the subsequent client-server session. A data-plane implementation has the benefits of running efficiently at line-rate, enabling the switch to take direct action on the packets (e.g., to rate-limit, block, or mark traffic based on the associated domain), and protecting the privacy of user information. We implemented Meta4 on an Intel Tofino switch and evaluated our prototype against packet traces from an operational network.

Similar Papers
  • Book Chapter

34 - Sending Data to a Server

  • Jan 01, 2004
  • Interactive QuickTime
  • Matthew Peterson
  • Research Article
  • Citations13

Visualizing and characterizing DNS lookup behaviors via log-mining

  • May 16, 2015
  • Neurocomputing
  • Qingnan Lai +4
  • Conference Article

An Abnormal Domain Name Generation Method Based on a Character-Level Model

  • Dec 16, 2022
  • Chunbing Wu +1
  • Book Chapter

CHAPTER 8 - Installing, Configuring as a Server

  • Jan 01, 2010
  • Eleventh Hour Linux+
  • Graham Speake
  • Research Article
  • Citations2

The Quest for Information Privacy in Africa: A Review Essay

  • Feb 01, 2017
  • Journal of Information Policy
  • Kinfe Micheal Yilma
  • Book Chapter
  • Citations2

Blockchain-Based Sealed-Bid Domain Name Auction Protocol

  • Jan 01, 2021
  • Lecture notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering
  • Genhua Lu +4
  • Preprint Article
  • Citations1

Heavy-Hitter Detection Entirely in the Data Plane

  • Jul 19, 2017
  • Vibhaalakshmi Sivaraman +4
  • Conference Article
  • Citations33

Neural reputation models learned from passive DNS data

  • Dec 01, 2017
  • Pierre Lison +1
  • Research Article
  • Citations74

ILNP: mobility, multi-homing, localised addressing and security through naming

  • Oct 20, 2009
  • Telecommunication Systems
  • Randall Atkinson +2
  • Research Article

Research on the algorithm for identifying VoIP session

  • Sep 01, 2008
  • Journal of Electronics (China)
  • Shumei Chen +2
  • Conference Article
  • Citations5

PicP-MUD: Profiling Information Content of Payloads in MUD Flows for IoT Devices

  • Jun 01, 2022
  • Arman Pashamokhtari +3
  • Conference Article
  • Citations20

A Survey on DNS Security Issues and Mitigation Techniques

  • May 01, 2019
  • Anju Ramdas +1
  • Conference Article
  • Citations27

Blacklist Ecosystem Analysis

  • Oct 12, 2015
  • Leigh Metcalf +1
  • Conference Article

Evaluating Web Protocol Threats: DNS Spoofing & TLS Weaknesses

  • Oct 13, 2025
  • Hamed Nazariyan +2
  • Research Article
  • Citations4

A Comprehensive Review of DNS-based Distributed Reflection Denial of Service (DRDoS) Attacks: State-of-the-Art

  • Dec 18, 2022
  • International Journal on Advanced Science Engineering and Information Technology
  • Riyadh Rahef Nuiaa +2
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.