RADD: A Real-time and Accurate Method for DDoS Detection Based on In-Network Computing

被引:0
|
作者
Wang, Wen [1 ,2 ]
Zhu, Shuyong [1 ]
Wu, Zhiyuan [1 ,2 ]
Lu, Lu [3 ]
Li, Zhiqiang [3 ]
Yang, Hongwei [3 ]
Zhang, Yujun [1 ,2 ]
机构
[1] Chinese Acad Sci, Inst Comp Technol, Beijing, Peoples R China
[2] Univ Chinese Acad Sci, Beijing, Peoples R China
[3] China Mobile Res Inst, Beijing, Peoples R China
基金
中国国家自然科学基金;
关键词
DDoS detection; in-network computing; programmable switch; P4;
D O I
10.1109/ICC51166.2024.10622656
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Distributed Denial-of-Service (DDoS) attacks pose formidable threats to the security and availability of critical Internet infrastructure. In-network computing technology brings new opportunities to address DDoS attacks due to its intrinsic data plane programmability and high performance. However, existing DDoS attacks detection schemes based on in-network computing are difficult to strike a balance between true positive rate and false positive rate, especially in low-rate DDoS attacks scenarios. In response to this challenge, we propose RADD, an entropy-based method to detect DDoS attacks in real time based on in-network computing. RADD measures the distribution of network traffic from the perspective of individual IP address to discern subtle fluctuations within network traffic, hence providing early indications of potential DDoS attacks. We implement a prototype of RADD over programmable switches and results show that our proposed method significantly outperforms the state-of-the-art or has equivalent accuracy in low-rate and high-rate DDoS attacks scenarios.
引用
收藏
页码:3316 / 3321
页数:6
相关论文
共 50 条
  • [21] An In-Network Reduction Algorithm for Real-time Wireless Sensor Network Applications
    Aquino, Andre L. L.
    Loureiro, Antonio A. F.
    Fernandes, Antonio O.
    Mini, Raquel A. F.
    WMUNEP'08 : PROCEEDINGS OF THE FOURTH ACM INTERNATIONAL WORKSHOP ON WIRELESS MULTIMEDIA NETWORKING AND PERFORMANCE MODELING, 2008, : 18 - 25
  • [22] Real-time DDoS attack detection based on Complex Event Processing for IoT
    Cardoso, Adeilson M. da S.
    Lopes, Rafael Fernandes
    Teles, Ariel Soares
    Veras Magalhaes, Fernando B.
    2018 IEEE/ACM THIRD INTERNATIONAL CONFERENCE ON INTERNET-OF-THINGS DESIGN AND IMPLEMENTATION (IOTDI 2020), 2018, : 273 - 274
  • [23] Towards a Unified In-Network DDoS Detection and Mitigation Strategy
    Friday, Kurt
    Kfoury, Elie
    Bou-Harb, Elias
    Crichigno, Jorge
    PROCEEDINGS OF THE 2020 6TH IEEE CONFERENCE ON NETWORK SOFTWARIZATION (NETSOFT 2020): BRIDGING THE GAP BETWEEN AI AND NETWORK SOFTWARIZATION, 2020, : 218 - 226
  • [24] The real-time computing model for a network based control system
    Wen, P
    Li, Y
    2004 8TH INTERNATIONAL CONFERENCE ON CONTROL, AUTOMATION, ROBOTICS AND VISION, VOLS 1-3, 2004, : 310 - 315
  • [25] Voltage sag real-time detection method based on feedback neural network
    Li, Cheng
    Yang, Bo
    Zou, Yun-Ping
    Ding, Hong-Fa
    Dianji yu Kongzhi Xuebao/Electric Machines and Control, 2010, 14 (09): : 19 - 25
  • [26] A fuzzy kernel-based method for real-time network intrusion detection
    Petrovskiy, M
    INNOVATIVE INTERNET COMMUNITY SYSTEMS, 2003, 2877 : 189 - 200
  • [27] Real-Time Target Detection Method Based on Lightweight Convolutional Neural Network
    Yun, Juntong
    Jiang, Du
    Liu, Ying
    Sun, Ying
    Tao, Bo
    Kong, Jianyi
    Tian, Jinrong
    Tong, Xiliang
    Xu, Manman
    Fang, Zifan
    FRONTIERS IN BIOENGINEERING AND BIOTECHNOLOGY, 2022, 10
  • [28] An Accurate and Real-Time Surface Defects Detection Method for Sawn Lumber
    Tu, Yaxin
    Ling, Zhigang
    Guo, Siyu
    Wen, He
    IEEE TRANSACTIONS ON INSTRUMENTATION AND MEASUREMENT, 2021, 70
  • [29] Real-time Reservoir Computing Network-based Systems for Detection Tasks on Visual Contents
    Jalalvand, Azarakhsh
    Van Wallendael, Glenn
    Van de Walle, Rik
    PROCEEDINGS 7TH INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE, COMMUNICATION SYSTEMS AND NETWORKS CICSYN 2015, 2015, : 146 - 151
  • [30] Real-Time Lateral Movement Detection Based on Evidence Reasoning Network for Edge Computing Environment
    Tian, Zhihong
    Shi, Wei
    Wang, Yuhang
    Zhu, Chunsheng
    Du, Xiaojiang
    Su, Shen
    Sun, Yanbin
    Guizani, Nadra
    IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2019, 15 (07) : 4285 - 4294