An Extremely Lightweight Approach for DDoS Detection at Home Gateways

An Extremely Lightweight Approach for DDoS Detection at Home Gateways
复制标题

家庭网关 DDoS 检测的极轻量级方法

DOI:
--
复制
发表时间:
2019
期刊:
2019 IEEE International Conference on Big Data (Big Data)
影响因子:
--
通讯作者:
D. Towsley
D. Towsley
中科院分区:
--
文献类型:
--
作者:
Gabriel Mendonça;Gustavo H. A. Santos;E. D. S. E. Silva;R. M. Leão;D. Menasché;D. Towsley

文献摘要

被引文献

相似文献

对互联网基础设施以及更广泛地说对其文化的一个主要威胁是DDoS攻击。为了减轻它们的影响,检测最好发生在靠近攻击源的地方,例如,在家庭路由器。然而,这些设备通常具有有限的资源和依赖于数据包检测的方法并不预示着这样的devices.We提出了一个轻量级的方法,DDoS检测,只采用网络接口字节和数据包计数。为了检测信息量如此有限的攻击,我们的关键见解在于训练分类器,以利用来自1,823个家庭用户的工作负载数据,这些数据在受控环境中生成攻击。在我们的实验中,我们选择了使用米拉伊和BASHLITE恶意软件生成的七个攻击向量。然后,我们对攻击向量进行与设备无关的检测,获得的F1分数通常高于0.99。为了科普DDoS攻击不断变化的性质,我们还报告了结果,表明当不同的攻击向量用于训练和测试时,所提出的方法的检测能力。
A major threat to the Internet infrastructure and, more broadly, to its culture is posed by DDoS attacks. To mitigate their impact, detection should preferably occur close to the attack origin, e.g., at home-routers. However, these devices typically have limited resources and an approach that relies on packet inspection does not bode well with such devices.We propose a lightweight approach for DDoS detection that solely employs network interface byte and packet counts. To detect attacks with such a limited amount of information, our key insight consists in training classifiers to make use of workload data from 1,823 home-users augmented with attacks generated in a controlled environment. In our experiments, we selected seven attack vectors generated using Mirai and BASHLITE malwares. We then conduct a device-agnostic detection of attacks vectors, obtaining F1 scores typically higher than 0.99. To cope with the evolving nature of DDoS attacks, we also report results indicating the detection power of the proposed methodology when different attack vectors are used for training and testing.