Towards a Unified In-Network DDoS Detection and Mitigation Strategy

被引:0
|
作者
Friday, Kurt [1 ]
Kfoury, Elie [2 ]
Bou-Harb, Elias [1 ]
Crichigno, Jorge [2 ]
机构
[1] Univ Texas San Antonio, Cyber Ctr Secur & Analyt, San Antonio, TX 78249 USA
[2] Univ South Carolina, Integrated Informat Technol, Columbia, SC 29208 USA
基金
美国国家科学基金会;
关键词
P4; Distributed Denial of Service; Data Plane; In-Network; Real-Time; ATTACKS;
D O I
暂无
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Distributed Denial of Service (DDoS) attacks have terrorized our networks for decades, and with attacks now reaching 1.7 Tbps, even the slightest latency in detection and subsequent remediation is enough to bring an entire network down. Though strides have been made to address such maliciousness within the context of Software Defined Networking (SDN), they have ultimately proven ineffective. Fortunately, P4 has recently emerged as a platform-agnostic language for programming the data plane and in turn allowing for customized protocols and packet processing. To this end, we propose a first-of-a-kind P4-based detection and mitigation scheme that will not only function as intended regardless of the size of the attack, but will also overcome the vulnerabilities of SDN that have characteristically been exploited by DDoS. Moreover, it successfully defends against the broad spectrum of currently relevant attacks while concurrently emphasizing the Quality of Service (QoS) of legitimate end-users and overall SDN functionality. We demonstrate the effectiveness of the proposed scheme using a software programmable P4-switch, namely, the Behavorial Model version 2 (BMv2), showing its ability to withstand a variety of DDoS attacks in real-time via three use cases that can be generalized to most contemporary attack vectors. Specifically, the results substantiate that the mechanism herein is orders of magnitude faster than traditional polling techniques (e.g., NetFlow or sFlow) while minimizing the impact on benign traffic. We concur that the approach's design particularities facilitate seamless and scalable deployments in high-speed networks requiring line-rate functionality, in addition to being generic enough to be integrated into viable network topologies.
引用
收藏
页码:218 / 226
页数:9
相关论文
共 50 条
  • [21] Optimized deep neural network based DDoS attack detection and bait mitigation process in software defined network
    Perumal, Karthika
    Arockiasamy, Karmel
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2023, 35 (12):
  • [22] Zero-Touch Security Management for mMTC Network Slices: DDoS Attack Detection and Mitigation
    Niboucha, Redouane
    Ben Saad, Sabra
    Ksentini, Adlen
    Challal, Yacine
    IEEE INTERNET OF THINGS JOURNAL, 2023, 10 (09) : 7800 - 7812
  • [23] Improved Network Monitoring Using Software-Defined Networking for DDoS Detection and Mitigation Evaluation
    J. Ramprasath
    V. Seethalakshmi
    Wireless Personal Communications, 2021, 116 : 2743 - 2757
  • [24] Improved Network Monitoring Using Software-Defined Networking for DDoS Detection and Mitigation Evaluation
    Ramprasath, J.
    Seethalakshmi, V.
    WIRELESS PERSONAL COMMUNICATIONS, 2021, 116 (03) : 2743 - 2757
  • [25] Ensemble-based DDoS Detection and Mitigation Model
    Bhatia, Sajal
    Schmidt, Desmond
    Mohay, George
    PROCEEDINGS OF THE FIFTH INTERNATIONAL CONFERENCE ON SECURITY OF INFORMATION AND NETWORKS, 2012, : 79 - 86
  • [26] DIDA: Distributed In-Network Defense Architecture Against Amplified Reflection DDoS Attacks
    Khooi, Xin Zhe
    Csikor, Levente
    Divakaran, Dinil Mon
    Kang, Min Suk
    PROCEEDINGS OF THE 2020 6TH IEEE CONFERENCE ON NETWORK SOFTWARIZATION (NETSOFT 2020): BRIDGING THE GAP BETWEEN AI AND NETWORK SOFTWARIZATION, 2020, : 277 - 281
  • [27] Advance DDOS detection and mitigation technique for securing cloud
    Zareapoor, Masoumeh
    Shamsolmoali, Pourya
    Alam, M. Afshar
    INTERNATIONAL JOURNAL OF COMPUTATIONAL SCIENCE AND ENGINEERING, 2018, 16 (03) : 303 - 310
  • [28] Mitigation and Detection of DDoS Attacks in Software Defined Networks
    Murtuza, Shariq
    Asawa, Krishna
    2018 ELEVENTH INTERNATIONAL CONFERENCE ON CONTEMPORARY COMPUTING (IC3), 2018, : 389 - 391
  • [29] SwitchAgg: A Further Step Towards In-Network Computing
    Yang, Fan
    Wang, Zhan
    Ma, Xiaoxiao
    Yuan, Guojun
    An, Xuejun
    2019 IEEE INTL CONF ON PARALLEL & DISTRIBUTED PROCESSING WITH APPLICATIONS, BIG DATA & CLOUD COMPUTING, SUSTAINABLE COMPUTING & COMMUNICATIONS, SOCIAL COMPUTING & NETWORKING (ISPA/BDCLOUD/SOCIALCOM/SUSTAINCOM 2019), 2019, : 36 - 45
  • [30] Real-Time In-Network Microburst Mitigation on Programmable Switch
    Lin, Yu-Jie
    Hung, Chi-Hsiang
    Wen, Charles H-P
    IEEE ACCESS, 2022, 10 : 2446 - 2456