Xatu: boosting existing DDoS detection systems using auxiliary signals

Xatu: boosting existing DDoS detection systems using auxiliary signals
复制标题

DOI:
10.1145/3555050.3569121
复制
发表时间:
2022-11
期刊:
Proceedings of the 18th International Conference on emerging Networking EXperiments and Technologies
影响因子:
--
通讯作者:
Zhiying Xu;Sivaramakrishnan Ramanathan;Alexander M. Rush;J. Mirkovic;Minlan Yu
Zhiying Xu;Sivaramakrishnan Ramanathan;Alexander M. Rush;J. Mirkovic;Minlan Yu
中科院分区:
其他
文献类型:
--
作者:
Zhiying Xu;Sivaramakrishnan Ramanathan;Alexander M. Rush;J. Mirkovic;Minlan Yu

文献摘要

相似文献

传统的DDoS攻击检测通过监控流量特征来检测攻击的发生。为了减少误报,这种检测通常是保守的-只有在观察到持续一段时间的异常行为后才发出警报。然而,当代攻击往往是短暂的,加上长时间的检测延迟意味着大多数攻击仍然到达并影响受害者。我们提出了Xatu,一个利用辅助信号来提高现有DDoS检测系统的准确性和及时性的系统。我们探讨两种类型的辅助信号,攻击准备信号和历史上的攻击。这些信号可以很容易地从许多ISP网络中的现有流量监控系统中挖掘出来。为了利用这些辅助信号进行攻击检测,我们提出了一个多时间尺度的LSTM模型,它可以从不同的辅助信号中导出长期和短期模式。然后,我们利用生存分析来快速检测攻击,同时最大限度地减少误报,从而减少成本。我们评估Xatu流量从一个大型ISP,使用商业防御警报数据来标记流行的攻击事件。Xatu将帮助商业防御系统清除高达44.1%的额外异常流量,并将其检测延迟中位数减少9.5分钟。
Traditional DDoS attack detection monitors volumetric traffic features to detect attack onset. To reduce false positives, such detection is often conservative---raising an alert only after a sustained period of observed anomalous behavior. However, contemporary attacks tend to be short, which combined with a long detection delay means that most of the attack still reaches and impacts the victim. We propose Xatu, a system that utilizes auxiliary signals to improve the accuracy and timeliness of existing DDoS detection systems. We explore two types of auxiliary signals, attack preparation signals and the history of prior attacks. These signals can be easily mined from existing traffic monitoring systems in many ISP networks. To leverage these auxiliary signals for attack detection, we propose a multi-timescale LSTM model, which derives both long-term and short-term patterns from diverse auxiliary signals. We then leverage survival analysis to quickly detect attacks when they occur while minimizing false positives and thus scrubbing costs. We evaluate Xatu on traffic from a large ISP, using commercial defense alert data to label prevalent attack events. Xatu would help the commercial defense scrub up to 44.1% additional anomalous traffic and would reduce its median detection delay by 9.5 minutes.1