Elastically Augmenting the Control-path Throughput in SDN to Deal with Internet DDoS Attacks

Elastically Augmenting the Control-path Throughput in SDN to Deal with Internet DDoS Attacks
复制标题

DOI:
10.1145/3559759
复制
发表时间:
2022-09
影响因子:
5.3
通讯作者:
Yuanjun Dai;An Wang;Yang Guo;Songqing Chen
Yuanjun Dai;An Wang;Yang Guo;Songqing Chen
中科院分区:
计算机科学4区
文献类型:
--
作者:
Yuanjun Dai;An Wang;Yang Guo;Songqing Chen

文献摘要

相似文献

分布式拒绝服务(DDoS)攻击在互联网上已经流行了几十年。尽管有各种各样的防御措施,它们的规模、频率和持续时间都在不断增长。新的网络范式,软件定义网络(SDN),也容易受到DDoS攻击。SDN使用逻辑集中控制,在维护全局网络视图和简化可编程性方面具有优势。当攻击发生时,交换机与其相关联的控制器之间的控制路径可能由于其有限的容量而变得拥塞。然而,SDN的数据平面可见性为在云计算环境中防御DDoS攻击提供了新的机会。为此,我们进行测量,以评估一些硬件交换机上的软件控制代理的吞吐量时,他们受到攻击。然后,我们设计了一个新的机制,称为苏格兰,使网络能够扩展其能力和处理DDoS攻击流量。在我们的设计中,拥塞作为一个指标,触发缓解机制。Scotch通过使用基于Open vSwitch的覆盖层弹性地扩展控制平面容量。Scotch利用大量vSwitch的高控制平面容量和商用物理交换机的高数据平面容量来增加SDN网络在异常(例如,DDoS攻击)流量激增。我们已经实现了一个原型和实验评估苏格兰威士忌。我们在小规模实验室环境和大规模GENI测试平台上的实验表明,Scotch可以在攻击时弹性地扩展控制信道带宽。
Distributed denial of service (DDoS) attacks have been prevalent on the Internet for decades. Albeit various defenses, they keep growing in size, frequency, and duration. The new network paradigm, Software-defined networking (SDN), is also vulnerable to DDoS attacks. SDN uses logically centralized control, bringing the advantages in maintaining a global network view and simplifying programmability. When attacks happen, the control path between the switches and their associated controllers may become congested due to their limited capacity. However, the data plane visibility of SDN provides new opportunities to defend against DDoS attacks in the cloud computing environment. To this end, we conduct measurements to evaluate the throughput of the software control agents on some of the hardware switches when they are under attacks. Then, we design a new mechanism, called Scotch, to enable the network to scale up its capability and handle the DDoS attack traffic. In our design, the congestion works as an indicator to trigger the mitigation mechanism. Scotch elastically scales up the control plane capacity by using an Open vSwitch-based overlay. Scotch takes advantage of both the high control plane capacity of a large number of vSwitches and the high data plane capacity of commodity physical switches to increase the SDN network scalability and resiliency under abnormal (e.g., DDoS attacks) traffic surges. We have implemented a prototype and experimentally evaluated Scotch. Our experiments in the small-scale lab environment and large-scale GENI testbed demonstrate that Scotch can elastically scale up the control channel bandwidth upon attacks.