Realtime DDoS Defense Using COTS SDN Switches via Adaptive Correlation Analysis

Realtime DDoS Defense Using COTS SDN Switches via Adaptive Correlation Analysis
复制标题

通过自适应相关分析使用 COTS SDN 交换机进行实时 DDoS 防御

DOI:
10.1109/tifs.2018.2805600
复制
发表时间:
2018-07-01
影响因子:
6.8
通讯作者:
Wu, Jianping
Wu, Jianping
中科院分区:
计算机科学1区
文献类型:
--
作者:
Zheng, Jing;Li, Qi;Wu, Jianping

文献摘要

被引文献

相似文献

分布式拒绝服务(DDoS)防御尽管已被广泛研究,但仍然是一个难题。现有的方法无法检测各种类型的DDoS攻击。特别是,由低速率且持续时间短的良性流量构建的新型复杂DDoS攻击(例如,Crossfire)更难以捕捉。此外,由于攻击流量可能隐藏在良性流量中,很难实施实时防御来抑制这些已检测到的攻击。软件定义网络(SDN)为解决这些问题开辟了新的途径。在本文中,我们提出了实时强化反DDoS行动(RADAR),通过在未修改的商用现成SDN交换机上建立自适应相关分析来检测和抑制DDoS攻击。它是一个实用的系统,可防御多种基于洪水攻击的DDoS攻击,例如链路洪水(包括Crossfire)、SYN洪水以及基于UDP的放大攻击,同时既不需要修改SDN交换机/协议,也不需要额外的设备。它通过识别可疑流中的攻击特征来准确检测攻击,并通过自适应相关分析定位攻击者(或受害者)以抑制攻击流量。我们使用开源的Floodlight控制器实现了RADAR原型,并通过基于真实硬件测试平台的实验在各种DDoS攻击下评估其性能。我们观察到我们的方案能够以可接受的开销成功检测并有效防御各种DDoS攻击。
Distributed denial-of-service (DDoS) defense is still a difficult problem though it has been extensively studied. The existing approaches are not capable of detecting various types of DDoS attacks. In particular, new emerging sophisticated DDoS attacks (e.g., Crossfire) constructed by low-rate and short-lived benign traffic are even more challenging to capture. Moreover, it is difficult to enforce realtime defense to throttle these detected attacks since the attack traffic can be concealed in benign traffic. Software defined networking (SDN) opens a new door to address these issues. In this paper, we propose Reinforcing Anti-DDoS Actions in Realtime (RADAR) to detect and throttle DDoS attacks via adaptive correlation analysis built upon unmodified commercial off-the-shelf SDN switches. It is a practical system to defend against a wide range of flooding-based DDoS attacks, e.g., link flooding (including Crossfire), SYN flooding, and UDP-based amplification attacks, while requiring neither modifications in SDN switches/protocols nor extra appliances. It accurately detects attacks by identifying attack features in suspicious flows, and locates attackers (or victims) to throttle the attack traffic by adaptive correlation analysis. We implement RADAR prototype using open source Floodlight controller, and evaluate its performance under various DDoS attacks by real hardware testbed based experiments. We observe that our scheme can successfully detect and effectively defend against various DDoS attacks with acceptable overhead.