Mew: Enabling Large-Scale and Dynamic Link-Flooding Defenses on Programmable Switches

被引:6
|
作者
Zhou, Huancheng [1 ]
Hong, Sungmin [1 ]
Liu, Yangyang [2 ]
Luo, Xiapu [2 ]
Li, Weichao [3 ]
Gu, Guofei [1 ]
机构
[1] Texas A&M Univ, SUCCESS Lab, College Stn, TX 77843 USA
[2] Hong Kong Polytech Univ, Hong Kong, Peoples R China
[3] Peng Cheng Lab, Shenzhen, Peoples R China
基金
美国国家科学基金会;
关键词
D O I
10.1109/SP46215.2023.10179404
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Link-flooding attacks (LFAs) can cut off the Internet connection to selected server targets and are hard to mitigate because adversaries use normal-looking and low-rate flows and can dynamically adjust the attack strategy. Traditional centralized defense systems cannot locally and efficiently suppress malicious traffic. Though emerging programmable switches offer an opportunity to bring defense systems closer to targeted links, their limited resource and lack of support for runtime reconfiguration limit their usage for link-flooding defenses. We present Mew1, a resource-efficient and runtime adaptable link-flooding defense system. Mew can counter various LFAs even when a massive number of flows are concentrated on a link, or when the attack strategy changes quickly. We design a distributed storage mechanism and a lossless state migration mechanism to reduce the storage bottleneck of programmable networks. We develop cooperative defense APIs to support multi-grained codetection and co-mitigation without excessive overhead. Mew's dynamic defense mechanism can constantly analyze network conditions and activate corresponding defenses without rebooting devices or interrupting other running functions. We develop a prototype of Mew by using real-world programmable switches, which are located in five cities. Our experiments show that the real-world prototype can defend against large-scale and dynamic LFAs effectively.
引用
收藏
页码:3178 / 3192
页数:15
相关论文
共 50 条
  • [1] CoDef: Collaborative Defense Against Large-Scale Link-Flooding Attacks
    Lee, Soo Bum
    Kang, Min Suk
    Gligor, Virgil D.
    PROCEEDINGS OF THE 2013 ACM INTERNATIONAL CONFERENCE ON EMERGING NETWORKING EXPERIMENTS AND TECHNOLOGIES (CONEXT '13), 2013, : 417 - 427
  • [2] Ripple: A Programmable, Decentralized Link-Flooding Defense Against Adaptive Adversaries
    Xing, Jiarong
    Wu, Wenqing
    Chen, Ang
    PROCEEDINGS OF THE 30TH USENIX SECURITY SYMPOSIUM, 2021, : 3865 - 3880
  • [3] Large-Scale Silicon Photonic Switches
    Wu, Ming C.
    Seok, Tae Joon
    Han, Sangyoon
    Quack, Niels
    2016 21ST OPTOELECTRONICS AND COMMUNICATIONS CONFERENCE (OECC) HELD JOINTLY WITH 2016 INTERNATIONAL CONFERENCE ON PHOTONICS IN SWITCHING (PS), 2016,
  • [4] Large-scale Silicon Photonic Switches
    Kwon, Kyungmok
    Seok, Tae Joon
    Henriksson, Johannes
    Luo, Jianheng
    Wu, Ming C.
    2019 PHOTONICS & ELECTROMAGNETICS RESEARCH SYMPOSIUM - SPRING (PIERS-SPRING), 2019, : 268 - 273
  • [5] Large-Scale Silicon Photonic Switches
    Wu, Ming C.
    Seok, Tae Joon
    2018 ASIA COMMUNICATIONS AND PHOTONICS CONFERENCE (ACP), 2018,
  • [6] Large-Scale Programmable Integrated Photonics
    Raz, Oded
    Stabile, Ripalta
    Melskens, Jimmy
    Pagliano, Francesco
    Li, Chenhui
    Sproncken, Christian C. M.
    Gumi-Audenis, Berta
    Lazdanaite, Emilija
    Kessels, Wilhelmus M. M.
    Voets, Ilja K.
    Mohammed, Mahir Asif
    2021 OPTICAL FIBER COMMUNICATIONS CONFERENCE AND EXPOSITION (OFC), 2021,
  • [7] A Dynamic Programmable Network for Large-Scale Scientific Data Transfer Using AmoebaNet
    Shah, Syed Asif Raza
    Noh, Seo-Young
    APPLIED SCIENCES-BASEL, 2019, 9 (21):
  • [8] Large-scale Silicon Photonic Switches with MEMS
    Seok, Tae Joon
    Han, Sangyoon
    Wu, Ming C.
    2017 IEEE PHOTONICS SOCIETY SUMMER TOPICAL MEETING SERIES (SUM), 2017,
  • [9] Enabling large-scale ligand discovery on the cloud
    Hawkins, Paul
    ABSTRACTS OF PAPERS OF THE AMERICAN CHEMICAL SOCIETY, 2016, 251
  • [10] NetScatter: Enabling Large-Scale Backscatter Networks
    Hessar, Mehrdad
    Najafi, Ali
    Gollakota, Shyamnath
    PROCEEDINGS OF THE 16TH USENIX SYMPOSIUM ON NETWORKED SYSTEMS DESIGN AND IMPLEMENTATION, 2019, : 271 - 283