• Complex
  • Title
  • Keyword
  • Abstract
  • Scholars
  • Journal
  • ISSN
  • Conference
成果搜索

author:

Sun, Tingxin (Sun, Tingxin.) [1] | Cai, Jiayi (Cai, Jiayi.) [2] | Guo, Kaiwei (Guo, Kaiwei.) [3] | Zhang, Dong (Zhang, Dong.) [4] (Scholars:张栋) | Chen, Xiang (Chen, Xiang.) [5] | Wu, Chunming (Wu, Chunming.) [6]

Indexed by:

CPCI-S EI

Abstract:

In Internet Service Provider (ISP) networks, Amplified Reflection DDoS (AR-DDoS) attack is one of the main attack categories, which launches gigabytes of traffic with little effort and minimal cost. Thus, the mitigation of AR-DDoS attacks has been considered as a crucial part. In particular, such mitigation requires full coverage (i.e., mitigating AR-DDoS attacks launched from any location) and low overhead (i.e., mitigation should avoid high latency that degrades user experience). However, existing solutions suffer from either limited coverage or high overhead. In this paper, we propose Aigis, a distributed framework that offers full-coverage and low-overhead mitigation of AR-DDoS attacks. Our key idea is to co-design top-of-rack (ToR) switches and end-hosts, which offers line-rate packet processing performance and fine-grained view inherently, to jointly execute endpoint verification. Specifically, Aigis selectively offloads mitigation operations between ToR switches and end-hosts and implements a network-wide epoch synchronization mechanism to guarantee reliable verification. It efficiently coordinates ToR switches and end-hosts to execute the entire mitigation task. We have implemented Aigis on a testbed comprising 32x100 Gbps Tofino switches. Testbed experiments indicate that Aigis achieves complete full coverage and orders of magnitude lower host-side overhead compared to existing solutions.

Keyword:

Amplified reflection ddos endpoint verification mitigation programmable switches

Community:

  • [ 1 ] [Sun, Tingxin]Fuzhou Univ, Sch Informat & Sci & Engn, Fuzhou, Peoples R China
  • [ 2 ] [Cai, Jiayi]Fuzhou Univ, Sch Informat & Sci & Engn, Fuzhou, Peoples R China
  • [ 3 ] [Guo, Kaiwei]Fuzhou Univ, Sch Informat & Sci & Engn, Fuzhou, Peoples R China
  • [ 4 ] [Zhang, Dong]Fuzhou Univ, Sch Informat & Sci & Engn, Fuzhou, Peoples R China
  • [ 5 ] [Chen, Xiang]Fuzhou Univ, Sch Informat & Sci & Engn, Fuzhou, Peoples R China
  • [ 6 ] [Zhang, Dong]Zhejiang Univ, Sch Comp Sci & Technol, Zhenjiang, Jiangsu, Peoples R China
  • [ 7 ] [Chen, Xiang]Zhejiang Univ, Sch Comp Sci & Technol, Zhenjiang, Jiangsu, Peoples R China
  • [ 8 ] [Wu, Chunming]Zhejiang Univ, Sch Comp Sci & Technol, Zhenjiang, Jiangsu, Peoples R China

Reprint 's Address:

Email:

Show more details

Related Keywords:

Source :

IEEE CONFERENCE ON GLOBAL COMMUNICATIONS, GLOBECOM

ISSN: 2334-0983

Year: 2023

Page: 1711-1716

Cited Count:

WoS CC Cited Count:

SCOPUS Cited Count:

ESI Highly Cited Papers on the List: 0 Unfold All

WanFang Cited Count:

Chinese Cited Count:

30 Days PV: 0

Online/Total:103/10036616
Address:FZU Library(No.2 Xuyuan Road, Fuzhou, Fujian, PRC Post Code:350116) Contact Us:0591-22865326
Copyright:FZU Library Technical Support:Beijing Aegean Software Co., Ltd. 闽ICP备05005463号-1