Towards a Unified In-Network DDoS Detection and Mitigation Strategy

被引:0
|
作者
Friday, Kurt [1 ]
Kfoury, Elie [2 ]
Bou-Harb, Elias [1 ]
Crichigno, Jorge [2 ]
机构
[1] Univ Texas San Antonio, Cyber Ctr Secur & Analyt, San Antonio, TX 78249 USA
[2] Univ South Carolina, Integrated Informat Technol, Columbia, SC 29208 USA
来源
PROCEEDINGS OF THE 2020 6TH IEEE CONFERENCE ON NETWORK SOFTWARIZATION (NETSOFT 2020): BRIDGING THE GAP BETWEEN AI AND NETWORK SOFTWARIZATION | 2020年
基金
美国国家科学基金会;
关键词
P4; Distributed Denial of Service; Data Plane; In-Network; Real-Time; ATTACKS;
D O I
暂无
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Distributed Denial of Service (DDoS) attacks have terrorized our networks for decades, and with attacks now reaching 1.7 Tbps, even the slightest latency in detection and subsequent remediation is enough to bring an entire network down. Though strides have been made to address such maliciousness within the context of Software Defined Networking (SDN), they have ultimately proven ineffective. Fortunately, P4 has recently emerged as a platform-agnostic language for programming the data plane and in turn allowing for customized protocols and packet processing. To this end, we propose a first-of-a-kind P4-based detection and mitigation scheme that will not only function as intended regardless of the size of the attack, but will also overcome the vulnerabilities of SDN that have characteristically been exploited by DDoS. Moreover, it successfully defends against the broad spectrum of currently relevant attacks while concurrently emphasizing the Quality of Service (QoS) of legitimate end-users and overall SDN functionality. We demonstrate the effectiveness of the proposed scheme using a software programmable P4-switch, namely, the Behavorial Model version 2 (BMv2), showing its ability to withstand a variety of DDoS attacks in real-time via three use cases that can be generalized to most contemporary attack vectors. Specifically, the results substantiate that the mechanism herein is orders of magnitude faster than traditional polling techniques (e.g., NetFlow or sFlow) while minimizing the impact on benign traffic. We concur that the approach's design particularities facilitate seamless and scalable deployments in high-speed networks requiring line-rate functionality, in addition to being generic enough to be integrated into viable network topologies.
引用
收藏
页码:218 / 226
页数:9
相关论文
共 50 条
  • [41] A Review of Anomaly Detection Techniques and Distributed Denial of Service (DDoS) on Software Defined Network (SDN)
    Khairi, Mutaz H. H.
    Ariffin, Sharifah H. S.
    Latiff, N. M. Abdul
    Abdullah, A. S.
    Hassan, M. K.
    ENGINEERING TECHNOLOGY & APPLIED SCIENCE RESEARCH, 2018, 8 (02) : 2724 - 2730
  • [42] An Improved Deep Learning Model for DDoS Detection Based on Hybrid Stacked Autoencoder and Checkpoint Network
    Mousa, Amthal K.
    Abdullah, Mohammed Najm
    FUTURE INTERNET, 2023, 15 (08):
  • [43] DDoSNet: Detection and prediction of DDoS attacks from realistic multidimensional dataset in IoT network environment
    Rao, Goda Srinivasa
    Patra, P. Santosh Kumar
    Narayana, V. A.
    Reddy, Avala Raji
    Reddy, G. N. V. Vibhav
    Eshwar, D.
    EGYPTIAN INFORMATICS JOURNAL, 2024, 27
  • [44] A comprehensive plane-wise review of DDoS attacks in SDN: Leveraging detection and mitigation through machine learning and deep learning
    Kalambe, Dhruv
    Sharma, Divyansh
    Kadam, Pushkar
    Surati, Shivangi
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2025, 235
  • [45] Comparative Analysis of Detection of DDoS Attacks in IEEE 802.15.4 Low Rate Wireless Personal Area Network
    Balarengadurai, C.
    Saraswathi, S.
    INTERNATIONAL CONFERENCE ON MODELLING OPTIMIZATION AND COMPUTING, 2012, 38 : 3855 - 3863
  • [46] Proactive DDoS detection: integrating packet marking, traffic analysis, and machine learning for enhanced network security
    Pasupathi, Subbulakshmi
    Kumar, Raushan
    Pavithra, L. K.
    CLUSTER COMPUTING-THE JOURNAL OF NETWORKS SOFTWARE TOOLS AND APPLICATIONS, 2025, 28 (03):
  • [47] A Local Feature Engineering Strategy to Improve Network Anomaly Detection †
    Carta, Salvatore
    Podda, Alessandro Sebastian
    Recupero, Diego Reforgiato
    Saia, Roberto
    FUTURE INTERNET, 2020, 12 (10) : 1 - 30
  • [48] Synoptic crow search with recurrent transformer network for DDoS attack detection in IoT-based smart homes
    Raipurkar, Abhijeet Ramesh
    International Journal of Web Engineering and Technology, 2024, 19 (03) : 330 - 355
  • [49] NTDA: The Mitigation of Denial of Service (DoS) Cyberattack Based on Network Traffic Detection Approach
    Tahboush, Muhannad
    Hamdan, Adel
    Alzobi, Firas
    Husni, Moath
    Adawy, Mohammad
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2024, 15 (03) : 692 - 698
  • [50] Deep Analysis of Risks and Recent Trends Towards Network Intrusion Detection System
    Shankar, D.
    George, G. Victo Sudha
    Naidu, J. N. S. S. Janardhana
    Madhuri, P. Shyamala
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2023, 14 (01) : 262 - 276