SDN-Assisted Network-Based Mitigation of Slow DDoS Attacks

04/18/2018
by   Thomas Lukaseder, et al.
0

Slow-running attacks against network applications are often not easy to detect, as the attackers behave according to the specification. The servers of many network applications are not prepared for such attacks, either due to missing countermeasures or because their default configurations ignores such attacks. The pressure to secure network services against such attacks is shifting more and more from the service operators to the network operators of the servers under attack. Recent technologies such as software-defined networking offer the flexibility and extensibility to analyze and influence network flows without the assistance of the target operator. Based on our previous work on a network-based mitigation, we have extended a framework to detect and mitigate slow-running DDoS attacks within the network infrastructure, but without requiring access to servers under attack. We developed and evaluated several identification schemes to identify attackers in the network solely based on network traffic information. We showed that by measuring the packet rate and the uniformity of the packet distances, a reliable identificator can be built, given a training period of the deployment network.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
08/16/2018

Mitigation of Flooding and Slow DDoS Attacks in a Software-Defined Network

Distributed denial of service (DDoS) attacks are a constant threat for s...
research
08/03/2018

An SDN-based Approach For Defending Against Reflective DDoS Attacks

Distributed Reflective Denial of Service (DRDoS) attacks are an immanent...
research
07/27/2019

Q-MIND: Defeating Stealthy DoS Attacks in SDN with a Machine-learning based Defense Framework

Software Defined Networking (SDN) enables flexible and scalable network ...
research
04/04/2020

Methods and Techniques for Dynamic Deployability of Software-Defined Security Services

With the recent trend of "network softwarisation", enabled by emerging t...
research
04/04/2019

20 Years of DDoS: a Call to Action

Distributed Denial of Service (DDoS) attacks are now 20 years old; what ...
research
06/24/2020

Anycast Agility: Adaptive Routing to Manage DDoS

IP Anycast is used for services such as DNS and Content Delivery Network...
research
12/30/2022

Detecting Forged Kerberos Tickets in an Active Directory Environment

Active Directory is the most popular service to manage users and devices...

Please sign up or login with your details

Forgot password? Click here to reset