ArOMA: An SDN based, autonomic DDoS mitigation framework

被引:46
作者
Sahay, Rishikesh [1 ,2 ]
Blanc, Gregory [1 ,2 ]
Zhang, Zonghua [2 ,3 ]
Debar, Herue [1 ,2 ]
机构
[1] Inst Mines Telecom, Telecom SudParis, Paris, France
[2] CNRS, UMR 5157, SAMOVAR, Paris, France
[3] Inst Mines Telecom, IMT Lille Douai, Lille, France
关键词
DDoS attacks; DDoS mitigation; Software Defined Networking; Anomaly detection; Security policy; MECHANISM;
D O I
10.1016/j.cose.2017.07.008
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Distributed Denial of Service (DDoS) attacks have been the plague of the Internet for more than two decades, despite the tremendous and continuous efforts from both academia and industry to counter them. The lessons learned from the past DDoS mitigation designs indicate that the heavy reliance on additional software modules and dedicated hardware devices seriously impede their widespread deployment. This paper proposes an autonomic DDoS defense framework, called ArOMA, that leverages the programmability and centralized manageability features of Software Defined Networking (SDN) paradigm. Specifically, ArOMA can systematically bridge the gaps between different security functions, ranging from traffic monitoring to anomaly, detection to mitigation, while sparing human operators from non-trivial interventions. It also facilitates the collaborations between ISPs and their customers on DDoS mitigation by logically distributing the essential security functions, allowing the ISP to handle DDoS traffic based on the requests of its customers. Our experimental results demonstrate that, in the face of DDoS flooding attacks, ArOMA can effectively maintain the performance of video streams at a satisfactory level. (C) 2017 Elsevier Ltd. All rights reserved.
引用
收藏
页码:482 / 499
页数:18
相关论文
共 48 条
[11]  
Braga R, 2010, C LOCAL COMPUT NETW, P408, DOI 10.1109/LCN.2010.5735752
[12]  
Damianou N, 2001, LECT NOTES COMPUT SC, V1995, P18
[13]  
Demetrescu C., 2003, STOC 03, P159
[14]  
Dhawan M, 2014, 22 ANN NETW DISTR SY
[15]   Understanding the Impact of Video Quality on User Engagement [J].
Dobrian, Florin ;
Awan, Asad ;
Joseph, Dilip ;
Ganjam, Aditya ;
Zhan, Jibin ;
Sekar, Vyas ;
Stoica, Ion ;
Zhang, Hui .
ACM SIGCOMM COMPUTER COMMUNICATION REVIEW, 2011, 41 (04) :362-373
[16]  
Dunbar L, 2014, INTERFACE N IN PRESS
[17]  
Eddy W, 2016, CUSTOMER CO IN PRESS
[18]  
Fayaz SK, 2015, PROCEEDINGS OF THE 24TH USENIX SECURITY SYMPOSIUM, P817
[19]  
Feinstein B, 2015, 4765 RFC
[20]  
Hsiao H-C, 2013, P ACM S INF COMP COM