A Scalable and Flexible DDoS Mitigation System Using Network Function Virtualization

被引:0
|
作者
Rashidi, Bahman [1 ]
Fung, Carol [1 ]
Rahman, Mohammad [2 ]
机构
[1] Virginia Commonwealth Univ, Dept Comp Sci, Richmond, VA 23284 USA
[2] Tennessee Technol Univ, Dept Comp Sci, Cookeville, TN USA
关键词
Distributed Denial of Service; Network Function Virtualization; DDoS mitigation; Scalable routing;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Distributed Denial of Service (DDoS) attacks remain one of the top threats to enterprise networks and ISPs nowadays. It can cause tremendous damage by bringing down online websites or services. Existing DDoS defense solutions either brings high cost such as upgrading existing firewall or IPS, or bring excessive traffic delay by using third-party cloud-based DDoS filtering services. In this work, we propose a DDoS defense framework that utilizes Network Function Virtualization (NFV) architecture to provide low cost and highly flexible solutions for enterprises. In particular, the system uses virtual network agents to perform attack traffic filtering before they are forwarded to the target server. Agents are created on demand to verify the authenticity of the source of packets, and drop spoofed packets in order protect the target server. Furthermore, we design a scalable and flexible dispatcher to forward packets to corresponding agents for processing. A bucket-based forwarding mechanism is used to improve the scalability of the dispatcher through batching forwarding. The dispatcher can also adapt to agent addition and removal. Our simulation results demonstrate that the dispatcher can effectively serve a large volume of traffic with low dropping rate. The system can successfully mitigate SYN flood attack by introducing minimal performance degradation to legitimate traffic.
引用
收藏
页数:6
相关论文
共 50 条
  • [1] Scalable DDoS Mitigation System
    Blazek, Petr
    Gerlich, Tomas
    Martinasek, Zdenek
    [J]. 2019 42ND INTERNATIONAL CONFERENCE ON TELECOMMUNICATIONS AND SIGNAL PROCESSING (TSP), 2019, : 617 - 620
  • [2] A Collaborative DDoS Defence Framework Using Network Function Virtualization
    Rashidi, Bahman
    Fung, Carol
    Bertino, Elisa
    [J]. IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2017, 12 (10) : 2483 - 2497
  • [3] CoPence: A Collaborative DDoS Defence Using Network Function Virtualization
    Rashidi, Bahman
    Fung, Carol
    [J]. 2016 12TH INTERNATIONAL CONFERENCE ON NETWORK AND SERVICE MANAGEMENT AND WORKSHOPS(CNSM 2016), 2016, : 160 - 166
  • [4] Dynamic DDoS Defense Resource Allocation using Network Function Virtualization
    Jakaria, A. H. M.
    Rashidi, Bahman
    Rahman, M. Ashiqur
    Fung, Carol
    Yang, Wei
    [J]. SDN-NFVSEC'17: PROCEEDINGS OF THE ACM INTERNATIONAL WORKSHOP ON SECURITY IN SOFTWARE DEFINED NETWORKS & NETWORK FUNCTION VIRTUALIZATION, 2017, : 37 - 42
  • [5] SCALABLE DDOS MITIGATION SYSTEM FOR DATA CENTERS
    Martinasek, Zdenek
    [J]. ADVANCES IN ELECTRICAL AND ELECTRONIC ENGINEERING, 2015, 13 (04) : 332 - 337
  • [6] Scalable Network Function Virtualization for Heterogeneous Middleboxes
    Zhang, Xuzhi
    Shao, Xiaozhe
    Provelengios, George
    Dumpala, Naveen Kumar
    Gao, Lixin
    Tessier, Russell
    [J]. 2017 IEEE 25TH ANNUAL INTERNATIONAL SYMPOSIUM ON FIELD-PROGRAMMABLE CUSTOM COMPUTING MACHINES (FCCM 2017), 2017, : 219 - 226
  • [7] Scalable Network Virtualization Using FPGAs
    Unnikrishnan, Deepak
    Vadlamani, Ramakrishna
    Liao, Yong
    Dwaraki, Abhishek
    Crenne, Jeremie
    Gao, Lixin
    Tessier, Russell
    [J]. FPGA 10, 2010, : 219 - 228
  • [8] A dynamic and scalable parallel Network Intrusion Detection System using intelligent rule ordering and Network Function Virtualization
    Haugerud, Harek
    Tran, Huy Nhut
    Aitsaadi, Nadjib
    Yazidi, Anis
    [J]. FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2021, 124 : 254 - 267
  • [9] ApplianceBricks: A Scalable Network Appliance Architecture for Network Function Virtualization
    Ma Shicong
    Wang Baosheng
    Zhang Xiaozhe
    Gao Xianming
    [J]. CHINA COMMUNICATIONS, 2016, 13 (01) : 32 - 42
  • [10] CoNFV: A Heterogeneous Platform for Scalable Network Function Virtualization
    Zhang, Xuzhi
    Shao, Xiaozhe
    Provelengios, George
    Dumpala, Naveen Kumar
    Gao, Lixin
    Tessier, Russell
    [J]. ACM TRANSACTIONS ON RECONFIGURABLE TECHNOLOGY AND SYSTEMS, 2021, 14 (01)