A Multi-Feature DDoS Detection Schema on P4 Network Hardware

2020 23rd Conference on Innovation in Clouds, Internet and Networks and Workshops (ICIN)(2020)

引用 28|浏览15
暂无评分
摘要
Data plane programmability is a promising technology that enables rapid control loops for the detection and mitigation of cyber-attacks. In this context, we propose an in-network architecture for DDoS attack detection combining important traffic metrics of malicious traffic. These pertain to number of flows and packet symmetry, maintained for protected subnets and utilized to identify anomalies. Appropriate alarms are triggered within time-based epochs and conveyed to external mitigation systems. We assess our DDoS detection schema in P4-enabled SmartNICs in terms of detection accuracy and packet processing performance. As input to our accuracy experiments we use real publicly available traffic traces. Furthermore, performance stress tests were conducted using high speed packet generators. Results exhibit that our approach is applicable in typical enterprise and/or carrier environments, featuring packet rates of 1-2 Mpps for l0G links.
更多
查看译文
关键词
DDoS detection,Data Plane Programmability,P4,SmartNIC
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要