跳到主要导航 跳到搜索 跳到主要内容

Poseidon: Mitigating Volumetric DDoS Attacks with Programmable Switches

  • Menghao Zhang
  • , Guanyu Li
  • , Shicheng Wang
  • , Chang Liu
  • , Ang Chen
  • , Hongxin Hu
  • , Guofei Gu
  • , Qi Li*
  • , Mingwei Xu*
  • , Jianping Wu
  • *此作品的通讯作者
  • Tsinghua University
  • Rice University
  • Clemson University
  • Texas A&M University

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

Distributed Denial-of-Service (DDoS) attacks have become a critical threat to the Internet. Due to the increasing number of vulnerable Internet of Things (IoT) devices, attackers can easily compromise a large set of nodes and launch high-volume DDoS attacks from the botnets. State-of-the-art DDoS defenses, however, have not caught up with the fast development of the attacks. Middlebox-based defenses can achieve high performance with specialized hardware; however, these defenses incur a high cost, and deploying new defenses typically requires a device upgrade. On the other hand, software-based defenses are highly flexible, but software-based packet processing leads to high performance overheads. In this paper, we propose POSEIDON, a system that addresses these limitations in today's DDoS defenses. It leverages emerging programmable switches, which can be reconfigured in the field without additional hardware upgrade. Users of POSEIDON can specify their defense strategies in a modular fashion in the form of a set of defense primitives; this can be further customized easily for each network and extended to include new defenses. POSEIDON then maps the defense primitives to run on programmable switches-and when necessary, on server software-for effective defense. When attacks change, POSEIDON can reconfigure the underlying defense primitives to respond to the new attack patterns. Evaluations using our prototype demonstrate that POSEIDON can effectively defend against high-volume attacks, easily support customization of defense strategies, and adapt to dynamic attacks with low overheads.

源语言英语
主期刊名27th Annual Network and Distributed System Security Symposium, NDSS 2020
出版商The Internet Society
ISBN(电子版)1891562614, 9781891562617
DOI
出版状态已出版 - 2020
已对外发布
活动27th Annual Network and Distributed System Security Symposium, NDSS 2020 - San Diego, 美国
期限: 23 2月 202026 2月 2020

出版系列

姓名27th Annual Network and Distributed System Security Symposium, NDSS 2020

会议

会议27th Annual Network and Distributed System Security Symposium, NDSS 2020
国家/地区美国
San Diego
时期23/02/2026/02/20

指纹

探究 'Poseidon: Mitigating Volumetric DDoS Attacks with Programmable Switches' 的科研主题。它们共同构成独一无二的指纹。

引用此