Euclid: A Fully In-Network, P4-Based Approach for Real-Time DDoS Attack Detection and Mitigation

被引:31
|
作者
Ilha, Alexandre da Silveira [1 ]
Lapolli, Angelo Cardoso [1 ]
Marques, Jonatas Adilson [1 ]
Gaspary, Luciano Paschoal [1 ]
机构
[1] Univ Fed Rio Grande do Sul, Inst Informat, BR-91501970 Porto Alegre, RS, Brazil
基金
美国国家科学基金会; 巴西圣保罗研究基金会;
关键词
Denial-of-service attack; Switches; Security; Middleboxes; Memory management; Delays; Computer crime; Software-defined networks; security; prototype implementation; testbed experimentation; SKETCH;
D O I
10.1109/TNSM.2020.3048265
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Distributed Denial-of-Service (DDoS) attacks have been steadily escalating in frequency, scale, and disruptiveness-with outbreaks reaching multiple terabits per second and compromising the availability of highly-resilient networked systems. Existing defenses require frequent interaction between forwarding and control planes, making it difficult to reach a satisfactory trade-off between accuracy (higher is better), resource usage, and defense response delay (lower is better). Recently, high-performance programmable data planes have made it possible to develop a new generation of mechanisms to analyze and manage traffic at line rate. In this article, we explore P4 language constructs and primitives to design Euclid, a fully in-network fine-grained, low-footprint, and low-delay traffic analysis mechanism for DDoS attack detection and mitigation. Euclid utilizes information-theoretic and statistical analysis to detect attacks and classify packets as either legitimate or malicious, thus enabling the enforcement of policies (e.g., discarding, inspection, or throttling) to prevent attack traffic from disrupting the operation of its victims. We experimentally evaluate our proposed mechanism using packet traces from CAIDA. The results indicate that Euclid can detect attacks with high accuracy (98.2%) and low delay (approximate to 250 ms), and correctly identify most of the attack packets (>96%) without affecting more than 1% of the legitimate traffic. Furthermore, our approach operates under a small resource usage footprint (tens of kilobytes of static random-access memory per 1 Gbps link and a few hundred ternary content-addressable memory entries), thus enabling its deployability on high-throughput, high-volume scenarios.
引用
收藏
页码:3121 / 3139
页数:19
相关论文
共 50 条
  • [1] RADD: A Real-time and Accurate Method for DDoS Detection Based on In-Network Computing
    Wang, Wen
    Zhu, Shuyong
    Wu, Zhiyuan
    Lu, Lu
    Li, Zhiqiang
    Yang, Hongwei
    Zhang, Yujun
    ICC 2024 - IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, 2024, : 3316 - 3321
  • [2] A Study on Traffic Asymmetry for Detecting DDoS Attack in P4-based SDN
    Lin, Ting-Yu
    Wang, Ching-Yuan
    Tuan, Ya-Pei
    Tsai, Meng-Hsun
    Chen, Yean-Ru
    JOURNAL OF INFORMATION SCIENCE AND ENGINEERING, 2022, 38 (06) : 1265 - 1283
  • [3] Real-Time In-Network Microburst Mitigation on Programmable Switch
    Lin, Yu-Jie
    Hung, Chi-Hsiang
    Wen, Charles H-P
    IEEE ACCESS, 2022, 10 : 2446 - 2456
  • [4] Real-time DDoS attack detection using FPGA
    Hoque, N.
    Kashyap, H.
    Bhattacharyya, D. K.
    COMPUTER COMMUNICATIONS, 2017, 110 : 48 - 58
  • [5] Real-Time DDoS Attack Detection System Using Big Data Approach
    Awan, Mazhar Javed
    Farooq, Umar
    Babar, Hafiz Muhammad Aqeel
    Yasin, Awais
    Nobanee, Haitham
    Hussain, Muzammil
    Hakeem, Owais
    Zain, Azlan Mohd
    SUSTAINABILITY, 2021, 13 (19)
  • [6] 5GDAD: A Deep Learning Approach for DDoS Attack Detection in 5G P4-based UPF
    Abu Bakar, Rana
    Alhamed, Faris
    Castoldi, Piero
    Sgambelluri, Andrea
    Olmos, Juan Jose Vegas
    Cugini, Filippo
    Paolucci, Francesco
    2024 IEEE 25TH INTERNATIONAL CONFERENCE ON HIGH PERFORMANCE SWITCHING AND ROUTING, HPSR 2024, 2024, : 185 - 190
  • [7] In-network P4-based Low Latency Robot Arm Control
    Rodriguez, Fabricio
    Rothenberg, Christian Esteve
    Pongracz, Gergely
    CONEXT'19 COMPANION: PROCEEDINGS OF THE 15TH INTERNATIONAL CONFERENCE ON EMERGING NETWORKING EXPERIMENTS AND TECHNOLOGIES, 2019, : 59 - 61
  • [8] Real-time DDoS attack detection based on Complex Event Processing for IoT
    Cardoso, Adeilson M. da S.
    Lopes, Rafael Fernandes
    Teles, Ariel Soares
    Veras Magalhaes, Fernando B.
    2018 IEEE/ACM THIRD INTERNATIONAL CONFERENCE ON INTERNET-OF-THINGS DESIGN AND IMPLEMENTATION (IOTDI 2020), 2018, : 273 - 274
  • [9] AN INTELLIGENT METHOD FOR REAL-TIME DETECTION OF DDOS ATTACK BASED ON FUZZY LOGIC
    Wang Jiangtao Yang Geng* (College of Computer
    JournalofElectronics(China), 2008, (04) : 511 - 518
  • [10] P4-based In-Network Telemetry for FPGAs in the Open Cloud Testbed and FABRIC
    Bal, Sandeep
    Han, Zhaoyang
    Handagala, Suranga
    CeviK, Mert
    Zink, Michael
    Leeser, Miriam
    IEEE INFOCOM 2024-IEEE CONFERENCE ON COMPUTER COMMUNICATIONS WORKSHOPS, INFOCOM WKSHPS 2024, 2024,