Affiliation:
1. Case Western Reserve University, Cleveland, OH, USA
2. National Institute of Standards and Technology, Gaithersburg, MD, USA
3. George Mason University, Fairfax, VA, USA
Abstract
Distributed denial of service (DDoS) attacks have been prevalent on the Internet for decades. Albeit various defenses, they keep growing in size, frequency, and duration. The new network paradigm, Software-defined networking (SDN), is also vulnerable to DDoS attacks. SDN uses logically centralized control, bringing the advantages in maintaining a global network view and simplifying programmability. When attacks happen, the control path between the switches and their associated controllers may become congested due to their limited capacity. However, the data plane visibility of SDN provides new opportunities to defend against DDoS attacks in the cloud computing environment. To this end, we conduct measurements to evaluate the throughput of the software control agents on some of the hardware switches when they are under attacks. Then, we design a new mechanism, called
Scotch
, to enable the network to scale up its capability and handle the DDoS attack traffic. In our design, the congestion works as an indicator to trigger the mitigation mechanism.
Scotch
elastically scales up the control plane capacity by using an Open vSwitch-based overlay.
Scotch
takes advantage of both the high control plane capacity of a large number of vSwitches and the high data plane capacity of commodity physical switches to increase the SDN network scalability and resiliency under abnormal (e.g., DDoS attacks) traffic surges. We have implemented a prototype and experimentally evaluated
Scotch
. Our experiments in the small-scale lab environment and large-scale GENI testbed demonstrate that
Scotch
can elastically scale up the control channel bandwidth upon attacks.
Funder
NSF
Commonwealth Cyber Initiative
Google Faculty Research Award
Publisher
Association for Computing Machinery (ACM)
Subject
Computer Networks and Communications
Reference45 articles.
1. Kupreev Oleg. 2021. DDoS Attacks in Q1 2020 | Securelist. Retrieved from https://securelist.com/ddos-attacks-in-q1-2020/96837/.
2. H. Ballani, P. Francis, T. Cao, and J. Wang. 2009. Making routers last longer with ViAggre. In NSDI.
3. T. Benson, A. Akella, and D. Maltz. 2010. Network traffic characteristics of data centers in the wild. In IMC.
4. GENI: A federated testbed for innovative network experiments
5. Zheng Cai, Alan L. Cox, and T. S. Eugene Ng. 2011. Maestro: Balancing Fairness, Latency and Throughput in the OpenFlow Control Plane. Technical Report TR11-07. Rice University.
Cited by
1 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献