Towards a Unified In-Network DDoS Detection and Mitigation Strategy

被引:0
|
作者
Friday, Kurt [1 ]
Kfoury, Elie [2 ]
Bou-Harb, Elias [1 ]
Crichigno, Jorge [2 ]
机构
[1] Univ Texas San Antonio, Cyber Ctr Secur & Analyt, San Antonio, TX 78249 USA
[2] Univ South Carolina, Integrated Informat Technol, Columbia, SC 29208 USA
来源
PROCEEDINGS OF THE 2020 6TH IEEE CONFERENCE ON NETWORK SOFTWARIZATION (NETSOFT 2020): BRIDGING THE GAP BETWEEN AI AND NETWORK SOFTWARIZATION | 2020年
基金
美国国家科学基金会;
关键词
P4; Distributed Denial of Service; Data Plane; In-Network; Real-Time; ATTACKS;
D O I
暂无
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Distributed Denial of Service (DDoS) attacks have terrorized our networks for decades, and with attacks now reaching 1.7 Tbps, even the slightest latency in detection and subsequent remediation is enough to bring an entire network down. Though strides have been made to address such maliciousness within the context of Software Defined Networking (SDN), they have ultimately proven ineffective. Fortunately, P4 has recently emerged as a platform-agnostic language for programming the data plane and in turn allowing for customized protocols and packet processing. To this end, we propose a first-of-a-kind P4-based detection and mitigation scheme that will not only function as intended regardless of the size of the attack, but will also overcome the vulnerabilities of SDN that have characteristically been exploited by DDoS. Moreover, it successfully defends against the broad spectrum of currently relevant attacks while concurrently emphasizing the Quality of Service (QoS) of legitimate end-users and overall SDN functionality. We demonstrate the effectiveness of the proposed scheme using a software programmable P4-switch, namely, the Behavorial Model version 2 (BMv2), showing its ability to withstand a variety of DDoS attacks in real-time via three use cases that can be generalized to most contemporary attack vectors. Specifically, the results substantiate that the mechanism herein is orders of magnitude faster than traditional polling techniques (e.g., NetFlow or sFlow) while minimizing the impact on benign traffic. We concur that the approach's design particularities facilitate seamless and scalable deployments in high-speed networks requiring line-rate functionality, in addition to being generic enough to be integrated into viable network topologies.
引用
收藏
页码:218 / 226
页数:9
相关论文
共 50 条
  • [21] DDoS attack detection based on global unbiased search strategy bee colony algorithm and artificial neural network
    Tian, Qiuting
    Han, Dezhi
    Du, Zhenxin
    INTERNATIONAL JOURNAL OF EMBEDDED SYSTEMS, 2019, 11 (05) : 584 - 593
  • [22] Towards DDoS detection mechanisms in Software-Defined Networking
    Cui, Yunhe
    Qian, Qing
    Guo, Chun
    Shen, Guowei
    Tian, Youliang
    Xing, Huanlai
    Yan, Lianshan
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2021, 190
  • [23] SDMTA: Attack Detection and Mitigation Mechanism for DDoS Vulnerabilities in Hybrid Cloud Environment
    Kautish, Sandeep
    Reyana, A.
    Vidyarthi, Ankit
    IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2022, 18 (09) : 6455 - 6463
  • [24] Network DDoS Layer 3/4/7 Mitigation via Dynamic Web Redirection
    Booth, Todd
    Andersson, Karl
    FUTURE NETWORK SYSTEMS AND SECURITY, 2016, 670 : 111 - 125
  • [25] An on-line DDoS attack Traceback and Mitigation System based on network performance monitoring
    Su, Wei-Tsung
    Lin, Tzu-Chieh
    Wu, Chun-Yi
    Hsu, Jang-Pong
    Kuo, Yau-Hwang
    10TH INTERNATIONAL CONFERENCE ON ADVANCED COMMUNICATION TECHNOLOGY, VOLS I-III: INNOVATIONS TOWARD FUTURE NETWORKS AND SERVICES, 2008, : 1467 - +
  • [26] Recursive Feature Elimination for DDoS Detection on Software Define Network
    Matsa, Lonnie Shumirai
    Zodi-Lusilao, Guy-Alain
    Shava, Fungai Bhunu
    2021 IST-AFRICA CONFERENCE (IST-AFRICA), 2021,
  • [27] Generalized Network Temperature for DDoS Detection through Renyi Entropy
    Wang, Xiang
    Zhang, Xing
    Wang, Changda
    2022 IEEE 22ND INTERNATIONAL CONFERENCE ON SOFTWARE QUALITY, RELIABILITY, AND SECURITY COMPANION, QRS-C, 2022, : 24 - 33
  • [28] ADVICE: Towards adaptive scheduling for data collection and DDoS detection in SDN
    Peng, Jin-cheng
    Cui, Yun-he
    Qian, Qing
    Guo, Chun
    Jiang, Chao-hui
    Li, Sai-fei
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2021, 63
  • [29] A hybrid method of entropy and SSAE-SVM based DDoS detection and mitigation mechanism in SDN
    Zhang Long
    Wang Jinsong
    COMPUTERS & SECURITY, 2022, 115
  • [30] A low-rate DDoS detection and mitigation for SDN using Renyi Entropy with Packet Drop
    Ahalawat, Anchal
    Babu, Korra Sathya
    Turuk, Ashok Kumar
    Patel, Sanjeev
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2022, 68