A Blockchain-enabled Multi-domain DDoS Collaborative Defense Mechanism

被引:1
|
作者
Feng, Huifen [1 ]
Liu, Ying [2 ]
Yan, Xincheng [2 ,3 ]
Zhou, Na [2 ,3 ]
Jiang, Zhihong [3 ]
机构
[1] Beijing Jiaotong Univ Beijing, Natl Engn Res Ctr Adv Network Technol, Beijing 100044, Peoples R China
[2] State Key Lab Mobile Network & Mobile Multimedia T, Shenzhen 518055, Peoples R China
[3] ZTE Corp, Nanjing 210012, Peoples R China
关键词
Autonomous System (AS); Blockchain; Smart Contract; IP traceback; Autonomous System Number (ASN); DDoS defense; PROBABILISTIC PACKET MARKING; IP; MITIGATION; NETWORK; SCHEME; ATTACK;
D O I
10.3837/tiis.2023.03.013
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Most of the existing Distributed Denial-of-Service mitigation schemes in Software-Defined Networking are only implemented in the network domain managed by a single controller. In fact, the zombies for attackers to launch large-scale DDoS attacks are actually not in the same network domain. Therefore, abnormal traffic of DDoS attack will affect multiple paths and network domains. A single defense method is difficult to deal with large-scale DDoS attacks. The cooperative defense of multiple domains becomes an important means to effectively solve cross-domain DDoS attacks. We propose an efficient multi-domain DDoS cooperative defense mechanism by integrating blockchain and SDN architecture. It includes attack traceability, inter-domain information sharing and attack mitigation. In order to reduce the length of the marking path and shorten the traceability time, we propose an AS-level packet traceability method called ASPM. We propose an information sharing method across multiple domains based on blockchain and smart contract. It effectively solves the impact of DDoS illegal traffic on multiple domains. According to the traceability results, we designed a DDoS attack mitigation method by replacing the ACL list with the IP address black/gray list. The experimental results show that our ASPM traceability method requires less data packets, high traceability precision and low overhead. And blockchain-based inter-domain sharing scheme has low cost, high scalability and high security. Attack mitigation measures can prevent illegal data flow in a timely and efficient manner.
引用
收藏
页码:916 / 937
页数:22
相关论文
共 50 条
  • [1] Hybrid Blockchain-Enabled Secure Microservices Fabric for Decentralized Multi-Domain Avionics Systems
    Xu, Ronghua
    Chen, Yu
    Blasch, Erik
    Aved, Alexander
    Chen, Genshe
    Shen, Dan
    [J]. SENSORS AND SYSTEMS FOR SPACE APPLICATIONS XIII, 2020, 11422
  • [2] NetChain: A Blockchain-Enabled Privacy-Preserving Multi-Domain Network Slice Orchestration Architecture
    He, Guobiao
    Su, Wei
    Gao, Shuai
    Liu, Ningchun
    Das, Sajal K.
    [J]. IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2022, 19 (01): : 188 - 202
  • [3] A Blockchain-Enabled Multi Domain Edge Computing Orchestrator
    Rathi, Vipin Kumar
    Chaudhary, Vinay
    Rajput, Nikhil Kumar
    Ahuja, Bhavya
    Jaiswal, Amit Kumar
    Gupta, Deepak
    Elhoseny, Mohamed
    Hammoudeh, Mohammad
    [J]. IEEE Internet of Things Magazine, 2020, 3 (02): : 30 - 36
  • [4] Blockchain-Enabled Federated Learning With Mechanism Design
    Toyoda, Kentaroh
    Zhao, Jun
    Zhang, Allan Neng Sheng
    Mathiopoulos, P. Takis
    [J]. IEEE ACCESS, 2020, 8 : 219744 - 219756
  • [5] A multi-point collaborative DDoS defense mechanism for IIoT environment
    Hongcheng Huang
    Peixin Ye
    Min Hu
    Jun Wu
    [J]. Digital Communications and Networks, 2023, 9 (02) : 590 - 601
  • [6] A multi-point collaborative DDoS defense mechanism for IIoT environment
    Huang, Hongcheng
    Ye, Peixin
    Hu, Min
    Wu, Jun
    [J]. DIGITAL COMMUNICATIONS AND NETWORKS, 2023, 9 (02) : 590 - 601
  • [7] Blockchain-enabled Collaborative Intrusion Detection in Software Defined Networks
    Fan, Wenjun
    Park, Younghee
    Kumar, Shubham
    Ganta, Priyatham
    Zhou, Xiaobo
    Chang, Sang-Yoon
    [J]. 2020 IEEE 19TH INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM 2020), 2020, : 968 - 975
  • [8] A distributed intrusion detection system to detect DDoS attacks in blockchain-enabled IoT network
    Kumar, Randhir
    Kumar, Prabhat
    Tripathi, Rakesh
    Gupta, Govind P.
    Garg, Sahil
    Hassan, Mohammad Mehedi
    [J]. JOURNAL OF PARALLEL AND DISTRIBUTED COMPUTING, 2022, 164 : 55 - 68
  • [9] Trustworthy and collaborative traceability management: Experts' feedback on a blockchain-enabled framework
    Demi, Selina
    Sanchez-Gordon, Mary
    Kristiansen, Monica
    Larrucea, Xabier
    [J]. JOURNAL OF SOFTWARE-EVOLUTION AND PROCESS, 2024,
  • [10] Trustworthy and collaborative traceability management: Experts’ feedback on a blockchain-enabled framework
    Demi, Selina
    Sánchez-Gordón, Mary
    Kristiansen, Monica
    Larrucea, Xabier
    [J]. Journal of Software: Evolution and Process, 36 (11):