Expect More from the Networking: DDoS Mitigation by FITT in Named Data Networking

02/24/2019
by   Zhiyi Zhang, et al.
0

Distributed Denial of Service (DDoS) attacks have plagued the Internet for decades, but defenses have not fundamentally outpaced attackers. Instead, the size and rate of growth in attacks have actually outpaced carriers' and DDoS mitigation services' growth. In this paper, we comprehensively examine ways in which Named Data Networking (NDN), a proposed data-centric Internet architecture, fundamentally addresses some of the principle weaknesses in today's DDoS defenses in IP networking. We argue that NDN's architectural changes (even when incrementally deployed) can make DDoS attacks fundamentally more difficult to launch and less effective. We present a new DDoS mitigation solution -- Fine-grained Interest Traffic Throttling FITT, to leverage NDN's features to combat DDoS in the Internet of Things (IoT) age. FITT enables the network to detect DDoS directly from feedback from victims, throttle DDoS traffic along its exact path in the network, and perform reinforcement control over the misbehaving entities at their sources. In cases like the Mirai attacks, where smart IoT devices (smart cameras, refrigerators, etc.) were able to cripple high-capacity service providers using diverse DDoS Tactics Techniques and Procedures (TTPs), FITT would be able to precisely squelch the attack traffic at its distributed sources, without disrupting other legitimate application traffic running on the same devices. FITT offers an incrementally deployable solution for service providers to effectuate the application-level remediation at the sources, which remains unattainable in today's DDoS market. Our extensive simulations results show that FITT can effectively throttle attack traffic in a short time and achieve over 99

READ FULL TEXT

page 1

page 2

page 3

page 4

research
07/11/2018

ThingPot: an interactive Internet-of-Things honeypot

The Mirai Distributed Denial-of-Service (DDoS) attack exploited security...
research
11/28/2017

Towards Information-Centric Networking (ICN) Naming for Internet of Things (IoT):The Case of Smart Campus

Information-Centric Networking (ICN) specifically Name Data Networking (...
research
02/08/2022

The role of Blockchain in DDoS attacks mitigation: techniques, open challenges and future directions

With the proliferation of new technologies such as Internet of Things (I...
research
04/04/2019

20 Years of DDoS: a Call to Action

Distributed Denial of Service (DDoS) attacks are now 20 years old; what ...
research
06/24/2020

Anycast Agility: Adaptive Routing to Manage DDoS

IP Anycast is used for services such as DNS and Content Delivery Network...
research
01/30/2023

Oscilloscope: Detecting BGP Hijacks in the Data Plane

The lack of security of the Internet routing protocol (BGP) has allowed ...
research
12/11/2020

Advanced Algorithms in Heterogeneous and Uncertain Networking Environments

Communication networks are used today everywhere and on every scale: sta...

Please sign up or login with your details

Forgot password? Click here to reset