On Implementation of Efficient Inline DDoS Detector Based on AATAC Algorithm

被引:1
作者
Wisniewski, Piotr [1 ]
Sosnowski, Maciej [1 ]
Burakowski, Wojciech [1 ]
机构
[1] Warsaw Univ Technol, Inst Telecommun, Warsaw, Poland
关键词
DDoS; Distributed Denial of Service; traffic anomaly detection; AATAC; performance; DPDK;
D O I
10.24425/ijet.2022.143899
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
Distributed Denial of Service (DDoS) attacks constitute a major threat in the current Internet. These cyber-attacks aim to flood the target system with tailored malicious network traffic overwhelming its service capacity and consequently severely limiting legitimate users from using the service. This paper builds on the state-of-the-art AATAC algorithm (Autonomous Algorithm for Traffic Anomaly Detection) and provides a concept of a dedicated inline DDoS detector capable of real-time monitoring of network traffic and near-real-time anomaly detection.The inline DDoS detector consists of two main elements: 1) inline probe(s) responsible for link-rate real-time processing and monitoring of network traffic with custom-built packet feature counters, and 2) an analyser that performs the near-real-time statistical analysis of these counters for anomaly detection. These elements communicate asynchronously via the Redis database, facilitating a wide range of deployment scenarios. The inline probes are based on COTS servers and utilise the DPDK framework (Data Plane Development Kit) and parallel packet processing on multiple CPU cores to achieve link rate traffic analysis, including tailored DPI analysis.
引用
收藏
页码:889 / 898
页数:10
相关论文
共 50 条
  • [21] The Improvement and Implementation of iSLIP Algorithm Based on FPGA
    Zeng Guang
    Yao Lin
    Zhao Ming
    Ma Yilan
    TRUSTWORTHY COMPUTING AND SERVICES (ISCTCS 2014), 2015, 520 : 260 - 266
  • [22] A multiple-data-based efficient global optimization algorithm and its parallel implementation for automotive body design
    Xu, Bing
    Cai, Yong
    ADVANCES IN MECHANICAL ENGINEERING, 2018, 10 (08)
  • [23] An Efficient SDN-Based DDoS Attack Detection and Rapid Response Platform in Vehicular Networks
    Yu, Yao
    Guo, Lei
    Liu, Ye
    Zheng, Jian
    Zong, Yue
    IEEE ACCESS, 2018, 6 : 44570 - 44579
  • [24] An Efficient DDoS Detection Method Based on Packet Grouping via Online Data Flow Processing
    He, Mingshu
    Zhao, Xiaowei
    Wang, Xiaojuan
    IEEE TRANSACTIONS ON SUSTAINABLE COMPUTING, 2025, 10 (02): : 202 - 216
  • [25] Online DDoS attack detection using Mahalanobis distance and Kernel-based learning algorithm
    Cakmakci, Salva Daneshgadeh
    Kemmerich, Thomas
    Ahmed, Tarem
    Baykal, Nazife
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2020, 168
  • [26] An Efficient and High-Speed Implementation of QRD-MGS Algorithm for STAP Application Based on Floating Point FPGAs
    Hasanikhah, Narjes
    Amin-Nejad, Siavash
    Darvish, Ghafar
    Moniri, M. R.
    JOURNAL OF CIRCUITS SYSTEMS AND COMPUTERS, 2020, 29 (03)
  • [27] SDN-based In-Band DDoS Detection Using Ensemble Learning Algorithm on IoT Edge
    Zang, Mingyuan
    Zaballa, Eder Ollora
    Dittmann, Lars
    25TH CONFERENCE ON INNOVATION IN CLOUDS, INTERNET AND NETWORKS (ICIN 2022), 2022, : 111 - 115
  • [28] Mitigate Volumetric DDoS Attack using Machine Learning Algorithm in SDN based IoT Network Environment
    Kumar, J.
    Rose, P. J. Arul Leena
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2023, 14 (01) : 559 - 568
  • [29] Defending DDoS attacks in software defined networking based on improved Shiryaev-Roberts detection algorithm
    Wang Xiulei
    Chen Ming
    Wei Xianglin
    Zhang Guomin
    JOURNAL OF HIGH SPEED NETWORKS, 2015, 21 (04) : 285 - 298
  • [30] An efficient clustering algorithm based on searching popularity peaks
    Motallebi, Hassan
    Malakoutifar, Najmeh
    PATTERN ANALYSIS AND APPLICATIONS, 2024, 27 (02)