Towards a Unified In-Network DDoS Detection and Mitigation Strategy

被引:0
|
作者
Friday, Kurt [1 ]
Kfoury, Elie [2 ]
Bou-Harb, Elias [1 ]
Crichigno, Jorge [2 ]
机构
[1] Univ Texas San Antonio, Cyber Ctr Secur & Analyt, San Antonio, TX 78249 USA
[2] Univ South Carolina, Integrated Informat Technol, Columbia, SC 29208 USA
基金
美国国家科学基金会;
关键词
P4; Distributed Denial of Service; Data Plane; In-Network; Real-Time; ATTACKS;
D O I
暂无
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Distributed Denial of Service (DDoS) attacks have terrorized our networks for decades, and with attacks now reaching 1.7 Tbps, even the slightest latency in detection and subsequent remediation is enough to bring an entire network down. Though strides have been made to address such maliciousness within the context of Software Defined Networking (SDN), they have ultimately proven ineffective. Fortunately, P4 has recently emerged as a platform-agnostic language for programming the data plane and in turn allowing for customized protocols and packet processing. To this end, we propose a first-of-a-kind P4-based detection and mitigation scheme that will not only function as intended regardless of the size of the attack, but will also overcome the vulnerabilities of SDN that have characteristically been exploited by DDoS. Moreover, it successfully defends against the broad spectrum of currently relevant attacks while concurrently emphasizing the Quality of Service (QoS) of legitimate end-users and overall SDN functionality. We demonstrate the effectiveness of the proposed scheme using a software programmable P4-switch, namely, the Behavorial Model version 2 (BMv2), showing its ability to withstand a variety of DDoS attacks in real-time via three use cases that can be generalized to most contemporary attack vectors. Specifically, the results substantiate that the mechanism herein is orders of magnitude faster than traditional polling techniques (e.g., NetFlow or sFlow) while minimizing the impact on benign traffic. We concur that the approach's design particularities facilitate seamless and scalable deployments in high-speed networks requiring line-rate functionality, in addition to being generic enough to be integrated into viable network topologies.
引用
收藏
页码:218 / 226
页数:9
相关论文
共 50 条
  • [41] IQR-based approach for DDoS detection and mitigation in SDN
    Swami, Rochak
    Dave, Mayank
    Ranga, Virender
    DEFENCE TECHNOLOGY, 2023, 25 : 76 - 87
  • [42] DDoS Attack Detection and Mitigation in SDN using Machine Learning
    Khashab, Fatima
    Moubarak, Joanna
    Feghali, Antoine
    Bassil, Carole
    PROCEEDINGS OF THE 2021 IEEE 7TH INTERNATIONAL CONFERENCE ON NETWORK SOFTWARIZATION (NETSOFT 2021): ACCELERATING NETWORK SOFTWARIZATION IN THE COGNITIVE AGE, 2021, : 395 - 401
  • [43] Time-based DDoS Detection and Mitigation for SDN Controller
    Dharma, I. Gde N.
    Muthohar, M. Fiqri
    Prayuda, Alvin J. D.
    Priagung, K.
    Choi, Deokjai
    2015 17TH ASIA-PACIFIC NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM APNOMS, 2015, : 550 - 553
  • [44] DDoS attacks in VoIP: a brief review of detection and mitigation techniques
    Narayanan, Sambath
    Manickam, Selvakumar
    Leau, Yu-Beng
    INTERNATIONAL JOURNAL OF ADVANCED AND APPLIED SCIENCES, 2016, 3 (09): : 90 - 96
  • [45] DDoS Detection and Mitigation in cloud via FogFiter: a defence mechanism
    Paharia, Bhumika
    Bhushan, Kriti
    2018 9TH INTERNATIONAL CONFERENCE ON COMPUTING, COMMUNICATION AND NETWORKING TECHNOLOGIES (ICCCNT), 2018,
  • [46] Efficient SYN spoofing Detection and Mitigation Scheme for DDoS attack
    Kavisankar, L.
    Chellappan, C.
    Venkatesan, S.
    Sivasankar, P.
    2017 SECOND INTERNATIONAL CONFERENCE ON RECENT TRENDS AND CHALLENGES IN COMPUTATIONAL MODELS (ICRTCCM), 2017, : 269 - 274
  • [47] DDoS Attack Detection Method and Mitigation Using Pattern of the Flow
    Sanmorino, Ahmad
    Yazid, Setiadi
    2013 INTERNATIONAL CONFERENCE OF INFORMATION AND COMMUNICATION TECHNOLOGY (ICOICT), 2013, : 12 - 16
  • [48] Collaborative detection and mitigation of DDoS in software-defined networks
    Tayfour, Omer Elsier
    Marsono, Muhammad Nadzir
    JOURNAL OF SUPERCOMPUTING, 2021, 77 (11): : 13166 - 13190
  • [49] Measuring in-network node similarity based on neighborhoods: a unified parametric approach
    Yu Yang
    Jian Pei
    Abdullah Al-Barakati
    Knowledge and Information Systems, 2017, 53 : 43 - 70
  • [50] Free in-network pricing as an entry-deterrence strategy
    Tingting He
    Dmitri Kuksov
    Chakravarthi Narasimhan
    Quantitative Marketing and Economics, 2017, 15 : 279 - 303