VFence: A Defense against Distributed Denial of Service Attacks using Network Function Virtualization

被引:32
|
作者
Jakaria, A. H. M. [1 ]
Yang, Wei [2 ]
Rashidi, Bahman [2 ]
Fung, Carol [2 ]
Rahman, M. Ashigur [1 ]
机构
[1] Tennessee Technol Univ, Dept Comp Sci, Cookeville, TN 38505 USA
[2] Virginia Commonwealth Univ, Dept Comp Sci, Richmond, VA USA
关键词
Distributed Denial of Service; Network Function Virtualization; Dynamic Defense Mechanism;
D O I
10.1109/COMPSAC.2016.219
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
With the exponential growth of the Internet use, cyber-threats are emerging rapidly. Distributed Denial of Service (DDoS) attack is one of the most common but damaging kinds of cyberattacks. A DDoS attack to a server typically prevents clients from receiving service by making the server overwhelmed with many invalid service requests. It is always a challenging problem to protect a system from DDoS attacks as it is not trivial to distinguish between an attack packet and a legitimate one. In this work, we have proposed VFence - a defense mechanism against DDoS attack that leverages the capability of the Network Function Virtualization (NFV) architecture. NFV is the technology of virtualizing network functions in virtual machines on commodity servers and it allows a flexible and dynamic implementation of the network functions. Our proposed mechanism uses network agents to intercept packets when the system is potentially under attack, to verify their authenticity, and to keep the server safe by dropping illegitimate packets. Since the attack intensity often varies, our NFV-based defense framework deploys agents dynamically to balance the attack load. Our simulation results demonstrate that the mechanism can successfully defeat the DDoS attacks by having all legitimate requests served, and the increase in the server's response time is insignificant compared to that of a successful DDoS attack.
引用
收藏
页码:431 / 436
页数:6
相关论文
共 50 条
  • [1] Distributed defense against distributed denial-of-service attacks
    Shi, W
    Xiang, Y
    Zhou, WL
    [J]. DISTRIBUTED AND PARALLEL COMPUTING, 2005, 3719 : 357 - 362
  • [2] Virtual Network Functions Placement for Defense Against Distributed Denial of Service Attacks
    Haddad-Vanier, Sonia
    Gicquel, Celine
    Boukhatem, Lila
    Lazri, Kahina
    Chaignon, Paul
    [J]. ICORES: PROCEEDINGS OF THE 8TH INTERNATIONAL CONFERENCE ON OPERATIONS RESEARCH AND ENTERPRISE SYSTEMS, 2019, : 142 - 150
  • [3] Characterization of defense mechanisms against distributed denial of service attacks
    Chen, LC
    Longstaff, TA
    Carley, KM
    [J]. COMPUTERS & SECURITY, 2004, 23 (08) : 665 - 678
  • [4] A Cooperative Mechanism to Defense Against Distributed Denial of Service Attacks
    Beitollahi, Hakem
    Deconinck, Geert
    [J]. TRUSTCOM 2011: 2011 INTERNATIONAL JOINT CONFERENCE OF IEEE TRUSTCOM-11/IEEE ICESS-11/FCST-11, 2011, : 11 - 20
  • [5] Defense mechanisms against Distributed Denial of Service attacks : A survey
    Manavi, Mousa Taghizadeh
    [J]. COMPUTERS & ELECTRICAL ENGINEERING, 2018, 72 : 26 - 38
  • [6] A game inspired defense mechanism against distributed denial of service attacks
    Bedi, Harkeerat
    Shiva, Sajjan
    Roy, Sankardas
    [J]. SECURITY AND COMMUNICATION NETWORKS, 2014, 7 (12) : 2389 - 2404
  • [7] A Hybrid Defense Technique for ISP Against the Distributed Denial of Service Attacks
    Moon, Young Hoon
    Choi, Suk Bong
    Kim, Huy Kang
    Yoo, Changsok
    [J]. APPLIED MATHEMATICS & INFORMATION SCIENCES, 2014, 8 (05): : 2347 - 2359
  • [8] VGuard: A Distributed Denial of Service Attack Mitigation Method using Network Function Virtualization
    Fung, Carol J.
    McCormick, Bill
    [J]. 2015 11TH INTERNATIONAL CONFERENCE ON NETWORK AND SERVICE MANAGEMENT (CNSM), 2015, : 64 - 70
  • [9] An Efficient Defense against Distributed Denial-of-Service Attacks using Congestion Path Marking
    Kim, Yoohwan
    Abd El Al, Ahmed
    Jo, Ju-Yeon
    Yang, Mei
    Jiang, Yingtao
    [J]. 2006 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, VOLS 1-12, 2006, : 2159 - 2164
  • [10] Defense Analysis Against Store and Forward Distributed Reflective Denial of Service Attacks
    Fraiwan, M.
    Al-Quran, Fidaa
    Al-Duwairi, Basheer
    [J]. PROCEEDINGS OF THE 2018 13TH INTERNATIONAL CONFERENCE ON INNOVATIONS IN INFORMATION TECHNOLOGY (IIT), 2018, : 111 - 116