An Extremely Lightweight Approach for DDoS Detection at Home Gateways
An Extremely Lightweight Approach for DDoS Detection at Home Gateways
复制标题
家庭网关 DDoS 检测的极轻量级方法
DOI:
--
复制
发表时间:
2019
期刊:
影响因子:
--
通讯作者:
D. Towsley
中科院分区:
文献类型:
--
作者:
Gabriel Mendonça;Gustavo H. A. Santos;E. D. S. E. Silva;R. M. Leão;D. Menasché;D. Towsley
A major threat to the Internet infrastructure and, more broadly, to its culture is posed by DDoS attacks. To mitigate their impact, detection should preferably occur close to the attack origin, e.g., at home-routers. However, these devices typically have limited resources and an approach that relies on packet inspection does not bode well with such devices.We propose a lightweight approach for DDoS detection that solely employs network interface byte and packet counts. To detect attacks with such a limited amount of information, our key insight consists in training classifiers to make use of workload data from 1,823 home-users augmented with attacks generated in a controlled environment. In our experiments, we selected seven attack vectors generated using Mirai and BASHLITE malwares. We then conduct a device-agnostic detection of attacks vectors, obtaining F1 scores typically higher than 0.99. To cope with the evolving nature of DDoS attacks, we also report results indicating the detection power of the proposed methodology when different attack vectors are used for training and testing.