Fighting Fire with Light: A Case for Defending DDoS Attacks Using the Optical Layer

02/23/2020
by   Matthew Hall, et al.
0

The DDoS attack landscape is growing at an unprecedented pace. Inspired by the recent advances in optical networking, we make a case for optical layer-aware DDoS defense (O-LAD) in this paper. Our approach leverages the optical layer to isolate attack traffic rapidly via dynamic reconfiguration of (backup) wavelengths using ROADMs—bridging the gap between (a) evolution of the DDoS attack landscape and (b) innovations in the optical layer (e.g., reconfigurable optics). We show that the physical separation of traffic profiles allows finer-grained handling of suspicious flows and offers better performance for benign traffic in the face of an attack. We present preliminary results modeling throughput and latency for legitimate flows while scaling the strength of attacks. We also identify a number of open problems for the security, optical, and systems communities: modeling diverse DDoS attacks (e.g., fixed vs. variable rate, detectable vs. undetectable), building a full-fledged defense system with optical advancements (e.g., OpenConfig), and optical layer-aware defenses for a broader class of attacks (e.g., network reconnaissance).

READ FULL TEXT

page 1

page 2

page 3

page 4

research
03/02/2023

Modeling and Exploration of Gain Competition Attacks in Optical Network-on-Chip Architectures

Network-on-Chip (NoC) enables energy-efficient communication between num...
research
06/27/2023

Catch Me If You Can: A New Low-Rate DDoS Attack Strategy Disguised by Feint

While collaborative systems provide convenience to our lives, they also ...
research
06/02/2020

Jamming-Aware Control Plane in Elastic Optical Networks

Physical layer security is essential in optical networks. In this paper,...
research
10/17/2019

A Least Squares Approach to the Static Traffic Analysis of High-Latency Anonymous Communication Systems

Mixes, relaying routers that hide the relation between incoming and outg...
research
06/18/2021

Light Lies: Optical Adversarial Attack

A significant amount of work has been done on adversarial attacks that i...
research
06/25/2023

ALBUS: a Probabilistic Monitoring Algorithm to Counter Burst-Flood Attacks

Modern DDoS defense systems rely on probabilistic monitoring algorithms ...
research
05/17/2020

Attack-aware Security Function Chain Reordering

Attack-awareness recognizes self-awareness for security systems regardin...

Please sign up or login with your details

Forgot password? Click here to reset