Mitigating LFA through segment rerouting in IoT environment with traceroute flow abnormality detection
Mitigating LFA through segment rerouting in IoT environment with traceroute flow abnormality detection
复制标题
通过跟踪路由流异常检测在物联网环境中通过分段重新路由来缓解 LFA
DOI:
10.1016/j.jnca.2020.102690
复制
发表时间:
2020-08
影响因子:
8.7
通讯作者:
Hu Ze
中科院分区:
文献类型:
--
作者:
Xie Lixia;Ding Ying;Yang Hongyu;Hu Ze
The Internet of Things (IoT) provides tremendous smart devices that are always connected to and interacting with the Internet. However, the development of IoT also promotes the threat of network attacks due to the billions of IoT devices vulnerable to hackers. Link-flooding attack (LFA) is a new type of DDoS attack used to flood the crucial network links. In IoT environment, LFA can be more easily launched by large-scale low-rate legitimate data flows with quite a low cost and is difficult to detect. Target areas in an enterprise network can be easily isolated since the crucial links are unavailable. Software defined network (SDN) architecture provides new opportunities to address this network security problem with the separation of data plane and control plane. Recently, segment routing (SR), which is an evolution of source routing, has been viewed as a promising technique for flow rerouting and failure recovery. SR is a lightweight easy-deployed scheme known for its flexibility, scalability, and applicability. Therefore, in this paper, we try to mitigate LFA with segment rerouting within the SDN architecture. With the comprehensive network-wide view of the data flows and links, we first design a monitoring mechanism to detect LFA based on the availability of the crucial links and traceroute flows. We consider the traceroute packet flows as time series with white Gaussian noise. A machine-learning-based auto-regression scheme is proposed to detect the abnormal increase in traceroute packets which indicates the launch of LFA. Then we use segment routing to detour the congested flows and alleviate the burden on the crucial links. Finally. the LFA bots will be identified and the malicious traffic will be blocked. Sufficient evaluations demonstrate that our LFA defense can efficiently detect LFA and preserve the network services, while only introduce a little signaling overhead between the control and data plane.
登录
查看更多内容
DOI:
10.1109/infocom.2016.7524507
发表时间:
2016-04
期刊:
IEEE INFOCOM 2016 - The 35th Annual IEEE International Conference on Computer Communications
影响因子:
--
作者:
C. Liaskos;Vasileios Kotronis;X. Dimitropoulos
通讯作者:
C. Liaskos;Vasileios Kotronis;X. Dimitropoulos
影响因子:
35.6
作者:
Zahra'a Abdullah;Imtiaz Ahmad;I. Hussain
通讯作者:
Zahra'a Abdullah;Imtiaz Ahmad;I. Hussain
DOI:
10.3724/sp.j.1001.2013.04390
发表时间:
2013-12
期刊:
Journal of Software
影响因子:
--
作者:
Qingyun Zuo;Ming Chen;Guangsong Zhao;Chang-you Xing;Guomin Zhang;Pei-cheng Jiang
通讯作者:
Qingyun Zuo;Ming Chen;Guangsong Zhao;Chang-you Xing;Guomin Zhang;Pei-cheng Jiang
影响因子:
8.7
作者:
Verma, Rahul Kumar;Pattanaik, K. K.;Saxena, Divya
通讯作者:
Saxena, Divya
DOI:
10.1016/j.jnca.2019.01.019
发表时间:
2019-04
期刊:
J. Netw. Comput. Appl.
影响因子:
--
作者:
Rishikesh Sahay;W. Meng;C. Jensen
通讯作者:
Rishikesh Sahay;W. Meng;C. Jensen