OPD: Network Packet Distribution after Achieving Equilibrium to Mitigate DDOS Attack

2021 IEEE 45TH ANNUAL COMPUTERS, SOFTWARE, AND APPLICATIONS CONFERENCE (COMPSAC 2021)(2021)

引用 1|浏览10
暂无评分
摘要
Crossfire Denial of Service (DDoS) is a new and organized type of attack to make the services of a target organization unavailable. The adversaries, in such attack, adveraremploy BOTs and decoy servers to flood critical links that are used to communicate with the target. In this paper, we propose an optimization framework, OPD (Optimized Packet Distributor), for distributing the packets in the most balanced way after a crossfire DDoS attack gets detected in a network. We formulate the network packet distribution problem as a non-linear link weight function and solved the optimization problem with a very efficient algorithm, Frank Wolf (FW). FW is the most efficient algorithm for solving convex set optimization problem. It achieves network equilibrium (or converges) with very few iterations. OPD will help the commonly used routing algorithm of Software Defined Network (SDN) by providing an optimized number of packets for each link. When a router sends a packet, it will follow the packet distribution proposed by OPD. We simulated a crossfire attack in NS2 simulator. The number of packets traveling in each link is collected for a given time frame from NS2. Based on this packet distribution, OPD proposes desired packet flows for the network. After evaluating the result of OPD, we have found that it can distribute the packets to the links that were less congested during the time of crossfire DDoS attack.
更多
查看译文
关键词
Re-Routing, Optimization, Network Modeling, Simulation, Denial of Service, Security
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要