• Complex
  • Title
  • Keyword
  • Abstract
  • Scholars
  • Journal
  • ISSN
  • Conference
成果搜索

author:

Sun, Tingxin (Sun, Tingxin.) [1] | Cai, Jiayi (Cai, Jiayi.) [2] | Guo, Kaiwei (Guo, Kaiwei.) [3] | Zhang, Dong (Zhang, Dong.) [4] (Scholars:张栋) | Chen, Xiang (Chen, Xiang.) [5] | Wu, Chunming (Wu, Chunming.) [6]

Indexed by:

EI

Abstract:

In Internet Service Provider (ISP) networks, Amplified Reflection DDoS (AR-DDoS) attack is one of the main attack categories, which launches gigabytes of traffic with little effort and minimal cost. Thus, the mitigation of AR-DDoS attacks has been considered as a crucial part. In particular, such mitigation requires full coverage (i.e., mitigating AR-DDoS attacks launched from any location) and low overhead (i.e., mitigation should avoid high latency that degrades user experience). However, existing solutions suffer from either limited coverage or high overhead. In this paper, we propose Aigis, a distributed framework that offers full-coverage and low-overhead mitigation of AR-DDoS attacks. Our key idea is to co-design top-of-rack (ToR) switches and end-hosts, which offers line-rate packet processing performance and fine-grained view inherently, to jointly execute endpoint verification. Specifically, Aigis selectively offloads mitigation operations between ToR switches and end-hosts and implements a network-wide epoch synchronization mechanism to guarantee reliable verification. It efficiently coordinates ToR switches and end-hosts to execute the entire mitigation task. We have implemented Aigis on a testbed comprising 32×100 Gbps Tofino switches. Testbed experiments indicate that Aigis achieves complete full coverage and orders of magnitude lower host-side overhead compared to existing solutions. © 2023 IEEE.

Keyword:

Community:

  • [ 1 ] [Sun, Tingxin]School of Information and Science and Engineering, Fuzhou University, Fuzhou, China
  • [ 2 ] [Cai, Jiayi]School of Information and Science and Engineering, Fuzhou University, Fuzhou, China
  • [ 3 ] [Guo, Kaiwei]School of Information and Science and Engineering, Fuzhou University, Fuzhou, China
  • [ 4 ] [Zhang, Dong]School of Information and Science and Engineering, Fuzhou University, Fuzhou, China
  • [ 5 ] [Zhang, Dong]School of Computer Science and Technology, Zhejiang University, Zhejiang, China
  • [ 6 ] [Chen, Xiang]School of Information and Science and Engineering, Fuzhou University, Fuzhou, China
  • [ 7 ] [Chen, Xiang]School of Computer Science and Technology, Zhejiang University, Zhejiang, China
  • [ 8 ] [Wu, Chunming]School of Computer Science and Technology, Zhejiang University, Zhejiang, China

Reprint 's Address:

Email:

Show more details

Related Keywords:

Related Article:

Source :

ISSN: 2334-0983

Year: 2023

Page: 1711-1716

Language: English

Cited Count:

WoS CC Cited Count:

SCOPUS Cited Count:

ESI Highly Cited Papers on the List: 0 Unfold All

WanFang Cited Count:

Chinese Cited Count:

30 Days PV: 0

Affiliated Colleges:

Online/Total:19/10057481
Address:FZU Library(No.2 Xuyuan Road, Fuzhou, Fujian, PRC Post Code:350116) Contact Us:0591-22865326
Copyright:FZU Library Technical Support:Beijing Aegean Software Co., Ltd. 闽ICP备05005463号-1