Offloading Real-time DDoS Attack Detection to Programmable Data Planes

被引:0
|
作者
Lapolli, Angelo Cardoso [1 ]
Marques, Jonatas Adilson [1 ]
Gaspary, Luciano Paschoal [1 ]
机构
[1] Univ Fed Rio Grande do Sul, Inst Informat, Rio Grande, RS, Brazil
基金
美国国家科学基金会;
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In recent years, Distributed Denial-of-Service (DDoS) attacks have escalated both in frequency and traffic volume, with outbreaks reaching rates up to the order of terabits per second and compromising the availability of supposedly highly resilient infrastructure (e.g., DNS and cloud-based web hosting). The reality is that existing detection solutions resort to a combination of mechanisms, such as packet sampling and transmission of gathered data to external software, which makes it very difficult (if at all possible) to reach a good compromise for accuracy (higher is better), resource usage footprint, and latency (lower is better). Data plane programmability has emerged as a promising approach to help meeting these requirements as forwarding devices can be configured to execute algorithms and examine traffic at line rate. In this paper, we explore P4 primitives to design a fine-grained, low-footprint, and low-latency traffic inspection mechanism for real-time DDoS attack detection. Our proposal-the first to be fully in-network-contributes to shed light on the challenges to implement sophisticated security logic on forwarding devices given that, to operate at high throughput, the inspection (and overall processing) of packets is subject to a small time budget (dozens of nanoseconds) and limited memory space (in the order of megabytes). We evaluate the proposed mechanism using packet traces from CAIDA. The results show that it can detect DDoS attacks entirely within the data plane with high accuracy (98.2%) and low latency (approximate to 250ms) while keeping device resource usage low (dozens of kilobytes in SRAM per 1Gbps link and a few hundred TCAM entries).
引用
收藏
页数:9
相关论文
共 50 条
  • [1] Real-time DDoS attack detection using FPGA
    Hoque, N.
    Kashyap, H.
    Bhattacharyya, D. K.
    COMPUTER COMMUNICATIONS, 2017, 110 : 48 - 58
  • [2] Real-Time DDoS Attack Detection System Using Big Data Approach
    Awan, Mazhar Javed
    Farooq, Umar
    Babar, Hafiz Muhammad Aqeel
    Yasin, Awais
    Nobanee, Haitham
    Hussain, Muzammil
    Hakeem, Owais
    Zain, Azlan Mohd
    SUSTAINABILITY, 2021, 13 (19)
  • [3] A Novel Real-Time DDoS Attack Detection Mechanism Based on MDRA Algorithm in Big Data
    Jia, Bin
    Ma, Yan
    Huang, Xiaohong
    Lin, Zhaowen
    Sun, Yi
    MATHEMATICAL PROBLEMS IN ENGINEERING, 2016, 2016
  • [4] Real-time DDoS flooding attack detection in intelligent transportation systems
    Karthikeyan, H.
    Usha, G.
    COMPUTERS & ELECTRICAL ENGINEERING, 2022, 101
  • [5] Real-time DDoS Attack Detection for Cisco IOS using NetFlow
    van der Steeg, Daniel
    Hofstede, Rick
    Sperotto, Anna
    Pras, Aiko
    PROCEEDINGS OF THE 2015 IFIP/IEEE INTERNATIONAL SYMPOSIUM ON INTEGRATED NETWORK MANAGEMENT (IM), 2015, : 972 - 977
  • [6] Real-time DDoS attack detection based on Complex Event Processing for IoT
    Cardoso, Adeilson M. da S.
    Lopes, Rafael Fernandes
    Teles, Ariel Soares
    Veras Magalhaes, Fernando B.
    2018 IEEE/ACM THIRD INTERNATIONAL CONFERENCE ON INTERNET-OF-THINGS DESIGN AND IMPLEMENTATION (IOTDI 2020), 2018, : 273 - 274
  • [7] AN INTELLIGENT METHOD FOR REAL-TIME DETECTION OF DDOS ATTACK BASED ON FUZZY LOGIC
    Wang Jiangtao Yang Geng* (College of Computer
    JournalofElectronics(China), 2008, (04) : 511 - 518
  • [8] A Real-Time Visualization Defense Framework for DDoS Attack
    Jin, Yiqiao
    Liang, Qidi
    Zhang, Jian
    Jin, Ou
    DATA SCIENCE, PT 1, 2017, 727 : 341 - 351
  • [9] An Effective Mechanism to Mitigate Real-Time DDoS Attack
    Abubakar, Rana
    Aldegheishem, Abdulaziz
    Majeed, Muhammad Faran
    Mehmood, Amjad
    Maryam, Hafsa
    Alrajeh, Nabil Ali
    Maple, Carsten
    Jawad, Muhammad
    IEEE ACCESS, 2020, 8 : 126215 - 126227
  • [10] Real Time Early Warning DDoS Attack Detection
    Xylogiannopoulos, Konstantinos
    Karampelas, Panagiotis
    Alhajj, Reda
    PROCEEDINGS OF THE 11TH INTERNATIONAL CONFERENCE ON CYBER WARFARE AND SECURITY (ICCWS 2016), 2016, : 344 - 351