Detecting DDoS Attacks within Milliseconds by Using FPGA-based Hardware Acceleration

被引:0
作者
Nagy, Balazs [1 ]
Orosz, Peter [2 ]
Tothfalusi, Tamas [1 ]
Kovacs, Laszlo [1 ]
Varga, Pal [2 ]
机构
[1] AITIA Int Inc, Telecommun Div, Budapest, Hungary
[2] Budapest Univ Technol & Econ, Dept Telecommun & Media Informat, Budapest, Hungary
来源
NOMS 2018 - 2018 IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM | 2018年
关键词
DDoS; intrusion detection; Data Center Networks; FPGA;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Timely detection and mitigation of Distributed Denial of Service (DDoS) attacks are still challenging for current datacenter and Internet packet exchange operators. Detecting volumetric attacks are in the range of seconds, whereas their mitigation is often in the range of minutes. Besides the fact that the attacks are effective until their mitigation is successful, there are further attacks that remain unnoticed by current equipment. These are hit-and-run attacks that last for a fraction of a second or a few seconds only, pushing the network or the targeted service towards an unstable state and evaporate. This paper presents an FPGA-based DDoS detector and its application. The detector is capable of detecting the top-9 DDoS attack types, the 96.67% of all DDoS attacks, and the so called hit-and-run attacks within milliseconds. The concept is validated through real-life use cases on attacks of a medium-sized datacenter network.
引用
收藏
页数:4
相关论文
共 14 条
  • [1] Akamai, 2017, STAT INT SEC REP
  • [2] [Anonymous], FORTIDDOS
  • [3] Arbor Networks, ARB APS
  • [4] An optimized reconfigurable power spectral density converter for real-time shrew DDoS attacks detection
    Chen, Hao
    Gaska, Thomas
    Chen, Yu
    Summerville, Douglas H.
    [J]. COMPUTERS & ELECTRICAL ENGINEERING, 2013, 39 (02) : 295 - 308
  • [5] Corero, 2017, DDOS TRENDS REP
  • [6] Hoque N., 2017, COMPUTER COMMUNICATI, V110
  • [7] Liss C., 2017, HIGH PERF SWITCH ROU
  • [8] Okafor K., 2015, 12 INCS AK NIG
  • [9] Orosz P, 2015, PROCEEDINGS OF THE 2015 IFIP/IEEE INTERNATIONAL SYMPOSIUM ON INTEGRATED NETWORK MANAGEMENT (IM), P954, DOI 10.1109/INM.2015.7140417
  • [10] Rossow C., 2014, NETW DISTR SYST SEC