Mitigating LFA through segment rerouting in IoT environment with traceroute flow abnormality detection

Mitigating LFA through segment rerouting in IoT environment with traceroute flow abnormality detection
复制标题

通过跟踪路由流异常检测在物联网环境中通过分段重新路由来缓解 LFA

DOI:
10.1016/j.jnca.2020.102690
复制
发表时间:
2020-08
影响因子:
8.7
通讯作者:
Hu Ze
Hu Ze
中科院分区:
计算机科学2区
文献类型:
--
作者:
Xie Lixia;Ding Ying;Yang Hongyu;Hu Ze

文献摘要

参考文献

被引文献

相似文献

物联网(IoT)提供了大量的智能设备,这些设备始终连接到互联网并与互联网交互。然而,物联网的发展也加剧了网络攻击的威胁,因为数十亿的物联网设备容易受到黑客的攻击。链路泛洪攻击(Link-flooding attack, LFA)是一种针对网络关键链路进行泛洪攻击的新型DDoS攻击。在物联网环境下,LFA更容易通过大规模低速率合法数据流发起,成本相当低,且难以检测。由于关键链路不可用,企业网络中的目标区域很容易被隔离。软件定义网络(SDN)体系结构通过数据平面和控制平面的分离为解决这一网络安全问题提供了新的机会。段路由(SR)是源路由的一种进化,近年来被认为是一种很有前途的流量重路由和故障恢复技术。SR是一种轻量级的易于部署的方案,以其灵活性、可伸缩性和适用性而闻名。因此,在本文中,我们尝试在SDN架构中使用段重路由来缓解LFA。在全面了解数据流和链路的全网视图的基础上,我们首先设计了一种基于关键链路和跟踪路由流的可用性来检测LFA的监控机制。我们将跟踪路由数据包流视为具有高斯白噪声的时间序列。提出了一种基于机器学习的自回归方案来检测traceroute数据包的异常增加,这表明LFA的启动。然后,我们采用分段路由绕过拥塞的流量,减轻关键链路的负担。最后。LFA机器人将被识别,恶意流量将被阻止。充分的评估表明,我们的LFA防御可以有效地检测LFA并保留网络服务,同时在控制平面和数据平面之间只引入少量的信令开销。
The Internet of Things (IoT) provides tremendous smart devices that are always connected to and interacting with the Internet. However, the development of IoT also promotes the threat of network attacks due to the billions of IoT devices vulnerable to hackers. Link-flooding attack (LFA) is a new type of DDoS attack used to flood the crucial network links. In IoT environment, LFA can be more easily launched by large-scale low-rate legitimate data flows with quite a low cost and is difficult to detect. Target areas in an enterprise network can be easily isolated since the crucial links are unavailable. Software defined network (SDN) architecture provides new opportunities to address this network security problem with the separation of data plane and control plane. Recently, segment routing (SR), which is an evolution of source routing, has been viewed as a promising technique for flow rerouting and failure recovery. SR is a lightweight easy-deployed scheme known for its flexibility, scalability, and applicability. Therefore, in this paper, we try to mitigate LFA with segment rerouting within the SDN architecture. With the comprehensive network-wide view of the data flows and links, we first design a monitoring mechanism to detect LFA based on the availability of the crucial links and traceroute flows. We consider the traceroute packet flows as time series with white Gaussian noise. A machine-learning-based auto-regression scheme is proposed to detect the abnormal increase in traceroute packets which indicates the launch of LFA. Then we use segment routing to detour the congested flows and alleviate the burden on the crucial links. Finally. the LFA bots will be identified and the malicious traffic will be blocked. Sufficient evaluations demonstrate that our LFA defense can efficiently detect LFA and preserve the network services, while only introduce a little signaling overhead between the control and data plane.
DOI: 10.1109/infocom.2016.7524507
发表时间: 2016-04
期刊: IEEE INFOCOM 2016 - The 35th Annual IEEE International Conference on Computer Communications
影响因子: --
作者:
C. Liaskos;Vasileios Kotronis;X. Dimitropoulos
通讯作者: C. Liaskos;Vasileios Kotronis;X. Dimitropoulos
DOI: 10.1109/comst.2018.2869754
发表时间: 2019
影响因子: 35.6
作者:
Zahra'a Abdullah;Imtiaz Ahmad;I. Hussain
通讯作者: Zahra'a Abdullah;Imtiaz Ahmad;I. Hussain
DOI: 10.3724/sp.j.1001.2013.04390
发表时间: 2013-12
期刊: Journal of Software
影响因子: --
作者:
Qingyun Zuo;Ming Chen;Guangsong Zhao;Chang-you Xing;Guomin Zhang;Pei-cheng Jiang
通讯作者: Qingyun Zuo;Ming Chen;Guangsong Zhao;Chang-you Xing;Guomin Zhang;Pei-cheng Jiang
DOI: 10.1016/j.jnca.2019.01.013
发表时间: 2019-03-15
影响因子: 8.7
作者:
Verma, Rahul Kumar;Pattanaik, K. K.;Saxena, Divya
通讯作者: Saxena, Divya
DOI: 10.1016/j.jnca.2019.01.019
发表时间: 2019-04
期刊: J. Netw. Comput. Appl.
影响因子: --
作者:
Rishikesh Sahay;W. Meng;C. Jensen
通讯作者: Rishikesh Sahay;W. Meng;C. Jensen