RADD: A Real-time and Accurate Method for DDoS Detection Based on In-Network Computing

被引:0
|
作者
Wang, Wen [1 ,2 ]
Zhu, Shuyong [1 ]
Wu, Zhiyuan [1 ,2 ]
Lu, Lu [3 ]
Li, Zhiqiang [3 ]
Yang, Hongwei [3 ]
Zhang, Yujun [1 ,2 ]
机构
[1] Chinese Acad Sci, Inst Comp Technol, Beijing, Peoples R China
[2] Univ Chinese Acad Sci, Beijing, Peoples R China
[3] China Mobile Res Inst, Beijing, Peoples R China
基金
中国国家自然科学基金;
关键词
DDoS detection; in-network computing; programmable switch; P4;
D O I
10.1109/ICC51166.2024.10622656
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Distributed Denial-of-Service (DDoS) attacks pose formidable threats to the security and availability of critical Internet infrastructure. In-network computing technology brings new opportunities to address DDoS attacks due to its intrinsic data plane programmability and high performance. However, existing DDoS attacks detection schemes based on in-network computing are difficult to strike a balance between true positive rate and false positive rate, especially in low-rate DDoS attacks scenarios. In response to this challenge, we propose RADD, an entropy-based method to detect DDoS attacks in real time based on in-network computing. RADD measures the distribution of network traffic from the perspective of individual IP address to discern subtle fluctuations within network traffic, hence providing early indications of potential DDoS attacks. We implement a prototype of RADD over programmable switches and results show that our proposed method significantly outperforms the state-of-the-art or has equivalent accuracy in low-rate and high-rate DDoS attacks scenarios.
引用
收藏
页码:3316 / 3321
页数:6
相关论文
共 50 条
  • [1] Euclid: A Fully In-Network, P4-Based Approach for Real-Time DDoS Attack Detection and Mitigation
    Ilha, Alexandre da Silveira
    Lapolli, Angelo Cardoso
    Marques, Jonatas Adilson
    Gaspary, Luciano Paschoal
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2021, 18 (03): : 3121 - 3139
  • [2] AN INTELLIGENT METHOD FOR REAL-TIME DETECTION OF DDOS ATTACK BASED ON FUZZY LOGIC
    Wang Jiangtao Yang Geng* (College of Computer
    JournalofElectronics(China), 2008, (04) : 511 - 518
  • [3] S-DDoS: Apache spark based real-time DDoS detection system
    Patil, Nilesh Vishwasrao
    Krishna, C. Rama
    Kumar, Krishan
    JOURNAL OF INTELLIGENT & FUZZY SYSTEMS, 2020, 38 (05) : 6527 - 6535
  • [4] Real-Time Hand Detection Method Based on Lightweight Network
    Jin, Fangrui
    Wang, Yangping
    Yong, Jiu
    Computer Engineering and Applications, 2023, 59 (14) : 192 - 200
  • [5] A METHOD FOR ACCURATE AUTOMATED REAL-TIME SEIZURE DETECTION
    OSORIO, I
    FREI, M
    LERNER, D
    WILKINSON, S
    EPILEPSIA, 1995, 36 : 104 - 104
  • [6] Leveraging In-Network Computing for Privacy-aware Real-time Surveillance mHealth Applications
    Rajhi, Syrine
    Elbiaze, Halima
    Gambs, Sebastien
    Glitho, Roch
    IEEE CONFERENCE ON GLOBAL COMMUNICATIONS, GLOBECOM, 2023, : 3203 - 3208
  • [7] An Accurate and Real-Time Detection Method for Concealed Slow HTTP DoS in Backbone Network
    Chen, Jinfeng
    Wu, Hua
    Wang, Suyue
    Cheng, Guang
    Hu, Xiaoyan
    ICT SYSTEMS SECURITY AND PRIVACY PROTECTION, IFIP SEC 2023, 2024, 679 : 207 - 221
  • [8] Real-time method for DDoS attacks detection based on self-similarity and wavelet analysis
    Ren Xunyi
    Wang Ruchuan
    Qi Zhenghua
    CHINESE JOURNAL OF ELECTRONICS, 2008, 17 (01): : 90 - 94
  • [9] Real-Time Detection of DDoS Attacks Based on Random Forest in SDN
    Ma, Ruikui
    Wang, Qiuqian
    Bu, Xiangxi
    Chen, Xuebin
    APPLIED SCIENCES-BASEL, 2023, 13 (13):
  • [10] Real-Time Risk Detection Method and Protection Strategy for Intelligent Ship Network Security Based on Cloud Computing
    Guo, Jian
    Guo, Hua
    SYMMETRY-BASEL, 2023, 15 (05):