Poster: A Fast Monitor for Slow Network Attacks

被引:0
|
作者
Wei, Cuidi [1 ]
Tu, Shaoyu [2 ]
Hasegawa, Toru [3 ]
Koizumi, Yuki [4 ]
Ramakrishnan, K. K. [2 ]
Takemasa, Junji [4 ]
Wood, Timothy [1 ]
机构
[1] George Washington Univ, Washington, DC 20052 USA
[2] Univ Calif Riverside, Riverside, CA USA
[3] Shimane Univ, Matsue, Shimane, Japan
[4] Osaka Univ, Osaka, Japan
关键词
Traffic monitor; slow network attacks; programmable switches; smartNIC;
D O I
10.1109/Cloud-Summit61220.2024.00032
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Recent work has demonstrated how programmable switches can effectively detect attack traffic, such as denial-of-service attacks in the midst of high-volume network traffic. However, these techniques primarily rely on sampling- or sketch-based data structures that can only be used to approximate the characteristics of dominant flows in the network. As a result, such techniques are unable to effectively detect slow attacks such as SYN port scans, SSH brute forcing, or HTTP connection exploits, which do so by stealthily adding only a few packets to the network. In this work we explore how the combination of programmable switches, Smart network interface cards (sNICs), and hosts can enable fine-grained analysis of every flow in a cloud network, even those with only a small number of packets. We focus on analyzing packets at the start of each flow, as those packets often can help indicate whether a flow is benign or suspicious, e.g., by detecting an attack which fails to complete the TCP handshake in order to waste server connection resources. Our approach leverages the high-speed processing of a programmable switch while overcoming its primary limitation - very limited memory capacity - by judiciously sending some state for processing to the sNIC or the host which typically has more memory, but lower bandwidth. Achieving this requires careful design of data structures on the switch, such as a bloom filter and flow logs, and communication protocols between the switch, sNIC, and host, to coordinate state.
引用
收藏
页码:153 / 156
页数:4
相关论文
共 50 条
  • [31] Poster: Off-path VoIP Interception Attacks
    Dai, Tianxiang
    Shulman, Haya
    Waidner, Michael
    2021 IEEE 41ST INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING SYSTEMS (ICDCS 2021), 2021, : 1122 - 1123
  • [32] POSTER: Mimicry Attacks against Wireless Link Signature
    Liu, Yao
    Ning, Peng
    PROCEEDINGS OF THE 18TH ACM CONFERENCE ON COMPUTER & COMMUNICATIONS SECURITY (CCS 11), 2011, : 801 - 803
  • [33] Poster: Efficient Exploration of Automotive Ranging Sensor Attacks
    Carter, Jack
    Ravi, Bhagawat Baanav Yedla
    Kabir, Md Rafiul
    Ray, Sandip
    PROCEEDINGS OF THE 2023 INTERNATIONAL SYMPOSIUM ON THEORY, ALGORITHMIC FOUNDATIONS, AND PROTOCOL DESIGN FOR MOBILE NETWORKS AND MOBILE COMPUTING, MOBIHOC 2023, 2023, : 589 - 591
  • [34] Poster: Rate Maximization under Reactive Jamming Attacks
    D'Oro, Salvatore
    Ekici, Eylem
    Palazzo, Sergio
    MOBIHOC '16: PROCEEDINGS OF THE 17TH ACM INTERNATIONAL SYMPOSIUM ON MOBILE AD HOC NETWORKING AND COMPUTING, 2016, : 367 - 368
  • [35] Bifurcation delay in a network of locally coupled slow-fast systems
    Premraj, D.
    Suresh, K.
    Banerjee, Tanmoy
    Thamilmaran, K.
    PHYSICAL REVIEW E, 2018, 98 (02)
  • [36] Morphology extraction of fetal electrocardiogram by slow-fast LSTM network
    Zhou, Ziqun
    Huang, Kejie
    Qiu, Yue
    Shen, Haibin
    Ming, Zhaoyan
    BIOMEDICAL SIGNAL PROCESSING AND CONTROL, 2021, 68
  • [37] Multimodal Fast-Slow Neural Network for learning engagement evaluation
    Zhang, Lizhao
    Hung, Jui-Long
    Du, Xu
    Li, Hao
    Hu, Zhuang
    DATA TECHNOLOGIES AND APPLICATIONS, 2023, 57 (03) : 418 - 435
  • [38] Morphology extraction of fetal electrocardiogram by slow-fast LSTM network
    Zhou, Ziqun
    Huang, Kejie
    Qiu, Yue
    Shen, Haibin
    Ming, Zhaoyan
    Biomedical Signal Processing and Control, 2021, 68
  • [39] Fast gels and slow gels: Understanding dynamics in a bioconjugated peptide network
    Tu, Raymond
    ABSTRACTS OF PAPERS OF THE AMERICAN CHEMICAL SOCIETY, 2019, 257
  • [40] Mitigating DDoS Attacks with Transparent and Intelligent Fast-Flux Swarm Network
    Lua, Ruiping
    Yow, Kin Choong
    IEEE NETWORK, 2011, 25 (04): : 28 - 33