A adaptive filtration based defense framework against DDoS

被引:0
|
作者
Zhang, Jian [1 ]
Zhou, Xiaxia [1 ]
Zhang, Wei [1 ]
Liang, Qidi [1 ]
Xiang, Fengtao [2 ]
机构
[1] Cent S Univ, Sch Informat Sci & Engn, Changsha, Hunan, Peoples R China
[2] Natl Univ Def Technol, Coll Mechatron Engn & Automat, Changsha, Hunan, Peoples R China
基金
中国国家自然科学基金;
关键词
DDoS; Spark Streaming; Spark; HBase; CUSUM; ATTACKS;
D O I
10.1109/ISPA/IUCC.2017.00113
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
While increasing cloud services are exposed to DDoS, DDoS defense has becoming more and more challenging. A single server with limited computing and memory resource can hardly handle large packet traces which are captured on fast links. In this paper, we propose a spark-streaming based online DDoS defense framework. First, we present a analysis model to identify abnormal packets. Second, we develop a defense model based on the statistics of abnormal packets. Our framework has two main advantages: (1) Our framework is configurable and with expert system functionality; the information maintained to detect threats is also leveraged during mitigation to effectively distinguishing legitimate from suspicious traffic; (2) Based on spark-streaming, our framework allows for parallel and distributed traffic analysis that can be deployed at high-speed network links. At the same time, by employing improved bloom-filter for approximated checks with low false positive/negative errors, it also reduces the space required to maintain the information leveraged for the threat detection and mitigation. The evaluation with data sets derived from real network traffic validates the performance of our framework in terms of detection accuracy, filtering efficiency, and monitoring overhead. The experiments show that our framework is able to detect DDoS attacks in the early stage of attack, to mitigate them by filtering out the majority of the abnormal packets while keeping a high percentage of the legitimate traffic unaffected.
引用
收藏
页码:729 / 736
页数:8
相关论文
共 50 条
  • [21] Implementation of an SDN-based Security Defense Mechanism Against DDoS Attacks
    Lin, Hsiao-Chung
    Wang, Ping
    JOINT 2016 INTERNATIONAL CONFERENCE ON ECONOMICS AND MANAGEMENT ENGINEERING (ICEME 2016) AND INTERNATIONAL CONFERENCE ON ECONOMICS AND BUSINESS MANAGEMENT (EBM 2016), 2016, : 377 - 383
  • [22] Software-Defined Edge Defense Against IoT-Based DDoS
    Ozcelik, Mert
    Chalabianloo, Niaz
    Gur, Gurkan
    2017 IEEE INTERNATIONAL CONFERENCE ON COMPUTER AND INFORMATION TECHNOLOGY (CIT), 2017, : 308 - 313
  • [23] SDN/NFV-based framework for autonomous defense against slow-rate DDoS attacks by using reinforcement learning
    Yungaicela-Naula, Noe M.
    Vargas-Rosales, Cesar
    Perez-Diaz, Jesus A.
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2023, 149 : 637 - 649
  • [24] Active network based DDoS Defense
    Sterne, D
    Djahandari, K
    Balupari, R
    La Cholter, W
    Babson, B
    Wilson, B
    Narasimhan, P
    Purtell, A
    DARPA ACTIVE NETWORKS CONFERENCE AND EXPOSITION, PROCEEDINGS, 2002, : 193 - 203
  • [25] A Novel Defense Scheme against DDOS Attack in VANET
    Pathre, Ayonija
    Agrawal, Chetan
    Jain, Anurag
    2013 TENTH INTERNATIONAL CONFERENCE ON WIRELESS AND OPTICAL COMMUNICATIONS NETWORKS (WOCN), 2013,
  • [26] Defense Mechanisms Against DDoS Attacks in SDN Environment
    Kalkan, Kubra
    Gur, Gurkan
    Alagoz, Fatih
    IEEE COMMUNICATIONS MAGAZINE, 2017, 55 (09) : 175 - 179
  • [27] Detection and Defense Mechanisms Against DDoS Attacks: A Review
    Pimpalkar, Archana S.
    Patil, A. R. Bhagat
    2015 INTERNATIONAL CONFERENCE ON INNOVATIONS IN INFORMATION, EMBEDDED AND COMMUNICATION SYSTEMS (ICIIECS), 2015,
  • [28] A novel defense scheme against DDOS attack in VANET
    2013, IEEE Computer Society
  • [29] A Cooperative Defense Framework Against Application-Level DDoS Attacks on Mobile Edge Computing Services
    Li, Hongjia
    Yang, Chang
    Wang, Liming
    Ansari, Nirwan
    Tang, Ding
    Huang, Xueqing
    Xu, Zhen
    Hu, Dan
    IEEE TRANSACTIONS ON MOBILE COMPUTING, 2023, 22 (01) : 1 - 18
  • [30] Detection and Defense Against DDoS Attack with IP Spoofing
    Mopari, I. B.
    Pukale, S. G.
    Dhore, M. L.
    ICCN: 2008 INTERNATIONAL CONFERENCE ON COMPUTING, COMMUNICATION AND NETWORKING, 2008, : 204 - 208