Towards a Unified In-Network DDoS Detection and Mitigation Strategy

被引:0
|
作者
Friday, Kurt [1 ]
Kfoury, Elie [2 ]
Bou-Harb, Elias [1 ]
Crichigno, Jorge [2 ]
机构
[1] Univ Texas San Antonio, Cyber Ctr Secur & Analyt, San Antonio, TX 78249 USA
[2] Univ South Carolina, Integrated Informat Technol, Columbia, SC 29208 USA
基金
美国国家科学基金会;
关键词
P4; Distributed Denial of Service; Data Plane; In-Network; Real-Time; ATTACKS;
D O I
暂无
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Distributed Denial of Service (DDoS) attacks have terrorized our networks for decades, and with attacks now reaching 1.7 Tbps, even the slightest latency in detection and subsequent remediation is enough to bring an entire network down. Though strides have been made to address such maliciousness within the context of Software Defined Networking (SDN), they have ultimately proven ineffective. Fortunately, P4 has recently emerged as a platform-agnostic language for programming the data plane and in turn allowing for customized protocols and packet processing. To this end, we propose a first-of-a-kind P4-based detection and mitigation scheme that will not only function as intended regardless of the size of the attack, but will also overcome the vulnerabilities of SDN that have characteristically been exploited by DDoS. Moreover, it successfully defends against the broad spectrum of currently relevant attacks while concurrently emphasizing the Quality of Service (QoS) of legitimate end-users and overall SDN functionality. We demonstrate the effectiveness of the proposed scheme using a software programmable P4-switch, namely, the Behavorial Model version 2 (BMv2), showing its ability to withstand a variety of DDoS attacks in real-time via three use cases that can be generalized to most contemporary attack vectors. Specifically, the results substantiate that the mechanism herein is orders of magnitude faster than traditional polling techniques (e.g., NetFlow or sFlow) while minimizing the impact on benign traffic. We concur that the approach's design particularities facilitate seamless and scalable deployments in high-speed networks requiring line-rate functionality, in addition to being generic enough to be integrated into viable network topologies.
引用
收藏
页码:218 / 226
页数:9
相关论文
共 50 条
  • [31] Detection and mitigation of link flooding-based DDoS attacks on a software defined network using network function virtualisation
    Murtuza, Shariq
    Asawa, Krishna
    INTERNATIONAL JOURNAL OF COMMUNICATION NETWORKS AND DISTRIBUTED SYSTEMS, 2024, 30 (02) : 202 - 226
  • [32] Towards a Unified Network for Robust Monocular Depth Estimation: Network Architecture, Training Strategy and Dataset
    Mochu Xiang
    Yuchao Dai
    Feiyu Zhang
    Jiawei Shi
    Xinyu Tian
    Zhensong Zhang
    International Journal of Computer Vision, 2024, 132 : 1012 - 1028
  • [33] Towards a Unified Network for Robust Monocular Depth Estimation: Network Architecture, Training Strategy and Dataset
    Xiang, Mochu
    Dai, Yuchao
    Zhang, Feiyu
    Shi, Jiawei
    Tian, Xinyu
    Zhang, Zhensong
    INTERNATIONAL JOURNAL OF COMPUTER VISION, 2024, 132 (04) : 1012 - 1028
  • [34] DDoS detection in high speed network
    Department of Computer Science and Technology, Nanjing University, Nanjing 210093, China
    不详
    Jisuanji Gongcheng, 2006, 10 (154-156):
  • [35] Random flow network modeling and simulations for DDoS attack mitigation
    Kong, JJ
    Mirza, M
    Shu, J
    Yoedhana, C
    Gerla, M
    Lu, SW
    2003 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, VOLS 1-5: NEW FRONTIERS IN TELECOMMUNICATIONS, 2003, : 487 - 491
  • [36] Collaborative detection and mitigation of DDoS in software-defined networks
    Omer Elsier Tayfour
    Muhammad Nadzir Marsono
    The Journal of Supercomputing, 2021, 77 : 13166 - 13190
  • [37] A DDoS Detection and Mitigation System Framework Based on Spark and SDN
    Yan, Qiao
    Huang, Wenyao
    SMART COMPUTING AND COMMUNICATION, SMARTCOM 2016, 2017, 10135 : 350 - 358
  • [38] DDoS Attack Detection and Mitigation Techniques in Cloud Computing Environment
    Devi, Kiruthika B. S.
    Subbulakshmi, T.
    PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON INTELLIGENT SUSTAINABLE SYSTEMS (ICISS 2017), 2017, : 512 - 517
  • [39] DDoS Attacks Detection and Mitigation in SDN using Machine Learning
    Rahman, Obaid
    Quraishi, Mohammad Ali Gauhar
    Lung, Chung-Horng
    2019 IEEE WORLD CONGRESS ON SERVICES (IEEE SERVICES 2019), 2019, : 184 - 189
  • [40] DDoS Attack Detection and Mitigation at SDN Data Plane Layer
    Abdulkarem, Huda Saleh
    Dawod, Ammar
    2020 IEEE 2ND GLOBAL POWER, ENERGY AND COMMUNICATION CONFERENCE (IEEE GPECOM2020), 2020, : 322 - 326