Mew: Enabling Large-Scale and Dynamic Link-Flooding Defenses on Programmable Switches

被引:6
|
作者
Zhou, Huancheng [1 ]
Hong, Sungmin [1 ]
Liu, Yangyang [2 ]
Luo, Xiapu [2 ]
Li, Weichao [3 ]
Gu, Guofei [1 ]
机构
[1] Texas A&M Univ, SUCCESS Lab, College Stn, TX 77843 USA
[2] Hong Kong Polytech Univ, Hong Kong, Peoples R China
[3] Peng Cheng Lab, Shenzhen, Peoples R China
基金
美国国家科学基金会;
关键词
D O I
10.1109/SP46215.2023.10179404
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Link-flooding attacks (LFAs) can cut off the Internet connection to selected server targets and are hard to mitigate because adversaries use normal-looking and low-rate flows and can dynamically adjust the attack strategy. Traditional centralized defense systems cannot locally and efficiently suppress malicious traffic. Though emerging programmable switches offer an opportunity to bring defense systems closer to targeted links, their limited resource and lack of support for runtime reconfiguration limit their usage for link-flooding defenses. We present Mew1, a resource-efficient and runtime adaptable link-flooding defense system. Mew can counter various LFAs even when a massive number of flows are concentrated on a link, or when the attack strategy changes quickly. We design a distributed storage mechanism and a lossless state migration mechanism to reduce the storage bottleneck of programmable networks. We develop cooperative defense APIs to support multi-grained codetection and co-mitigation without excessive overhead. Mew's dynamic defense mechanism can constantly analyze network conditions and activate corresponding defenses without rebooting devices or interrupting other running functions. We develop a prototype of Mew by using real-world programmable switches, which are located in five cities. Our experiments show that the real-world prototype can defend against large-scale and dynamic LFAs effectively.
引用
收藏
页码:3178 / 3192
页数:15
相关论文
共 50 条
  • [31] Large-Scale, MEMS-Actauated Silicon Photonic Switches
    Wu, Ming C.
    Seok, Tae Joon
    Han, Sangyoon
    Quack, Niels
    2015 INTERNATIONAL CONFERENCE ON PHOTONICS IN SWITCHING (PS), 2015, : 124 - 126
  • [32] Large-scale silicon photonic switches with movable directional couplers
    Han, Sangyoon
    Seok, Tae Joon
    Quack, Niels
    Yoo, Byung-Wook
    Wu, Ming C.
    OPTICA, 2015, 2 (04): : 370 - 375
  • [33] A general expansion architecture for large-scale multicast ATM switches
    Byun, SH
    Sung, DK
    IEICE TRANSACTIONS ON COMMUNICATIONS, 1997, E80B (11) : 1671 - 1679
  • [34] Extending commodity OpenFlow switches for large-scale HPC deployments
    Benito, Mariano
    Vallejo, Enrique
    Beivide, Ramon
    Izu, Cruz
    2017 IEEE 3RD INTERNATIONAL WORKSHOP ON HIGH-PERFORMANCE INTERCONNECTION NETWORKS IN THE EXASCALE AND BIG-DATA ERA (IEEE HIPINEB 2017), 2017, : 41 - 48
  • [35] LARGE-SCALE FIELD APPLICATION OF MICELLAR-POLYMER FLOODING
    HOWELL, JC
    MCATEE, RW
    SNYDER, WO
    TONSO, KL
    JOURNAL OF PETROLEUM TECHNOLOGY, 1979, 31 (06): : 690 - 696
  • [36] Revisiting Defenses against Large-Scale Online Password Guessing Attacks
    Alsaleh, Mansour
    Mannan, Mohammad
    van Oorschot, P. C.
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2012, 9 (01) : 128 - 141
  • [37] Large-Scale Dynamic Controller Placement
    ul Huque, Md Tanvir Ishtaique
    Si, Weisheng
    Jourjon, Guillaume
    Gramoli, Vincent
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2017, 14 (01): : 63 - 76
  • [38] Dynamic sharing of large-scale visualization
    Huang, Jian
    Liu, Huadong
    Beck, Micah
    Gaston, Andrew
    Gao, Jinzhu
    Moore, Terry
    IEEE COMPUTER GRAPHICS AND APPLICATIONS, 2007, 27 (01) : 20 - 25
  • [39] DYNAMIC FACTORIZATION IN LARGE-SCALE OPTIMIZATION
    BROWN, GG
    OLSON, MP
    MATHEMATICAL PROGRAMMING, 1994, 64 (01) : 17 - 51
  • [40] Programmable quantum circuits in a large-scale photonic waveguide array
    Yang, Yang
    Chapman, Robert J.
    Youssry, Akram
    Haylock, Ben
    Lenzini, Francesco
    Lobino, Mirko
    Peruzzo, Alberto
    NPJ QUANTUM INFORMATION, 2025, 11 (01)