ArOMA: An SDN based, autonomic DDoS mitigation framework

被引:46
作者
Sahay, Rishikesh [1 ,2 ]
Blanc, Gregory [1 ,2 ]
Zhang, Zonghua [2 ,3 ]
Debar, Herue [1 ,2 ]
机构
[1] Inst Mines Telecom, Telecom SudParis, Paris, France
[2] CNRS, UMR 5157, SAMOVAR, Paris, France
[3] Inst Mines Telecom, IMT Lille Douai, Lille, France
关键词
DDoS attacks; DDoS mitigation; Software Defined Networking; Anomaly detection; Security policy; MECHANISM;
D O I
10.1016/j.cose.2017.07.008
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Distributed Denial of Service (DDoS) attacks have been the plague of the Internet for more than two decades, despite the tremendous and continuous efforts from both academia and industry to counter them. The lessons learned from the past DDoS mitigation designs indicate that the heavy reliance on additional software modules and dedicated hardware devices seriously impede their widespread deployment. This paper proposes an autonomic DDoS defense framework, called ArOMA, that leverages the programmability and centralized manageability features of Software Defined Networking (SDN) paradigm. Specifically, ArOMA can systematically bridge the gaps between different security functions, ranging from traffic monitoring to anomaly, detection to mitigation, while sparing human operators from non-trivial interventions. It also facilitates the collaborations between ISPs and their customers on DDoS mitigation by logically distributing the essential security functions, allowing the ISP to handle DDoS traffic based on the requests of its customers. Our experimental results demonstrate that, in the face of DDoS flooding attacks, ArOMA can effectively maintain the performance of video streams at a satisfactory level. (C) 2017 Elsevier Ltd. All rights reserved.
引用
收藏
页码:482 / 499
页数:18
相关论文
共 48 条
[1]   IP traceback using header compression [J].
Aljifri, H ;
Smets, M ;
Pons, A .
COMPUTERS & SECURITY, 2003, 22 (02) :136-151
[2]  
[Anonymous], 2013, P 2 ACM SIGCOMM WORK, DOI DOI 10.1145/2491185.2491199
[3]  
[Anonymous], 2015, P 2015 NETW DISTR SY
[4]  
[Anonymous], 2014, P 2014 WORKSHOP DESI
[5]  
[Anonymous], P ISOC NETW DISTR SY
[6]  
[Anonymous], PROC ESORICS
[7]  
Arbor Networks, TECHNICAL REPORT
[8]  
Bai CY, 2004, IEEE IPCCC, P49
[9]   On deterministic packet marking [J].
Belenky, Andrey ;
Ansari, Nirwan .
COMPUTER NETWORKS, 2007, 51 (10) :2677-2700
[10]  
Benton K., 2013, P 2 ACM SIGCOMM WORK, P151, DOI [DOI 10.1145/2491185.2491222, 10.1145/2491185.2491222]