4.7 Article

SmartDefense: A distributed deep defense against DDoS attacks with edge computing

期刊

COMPUTER NETWORKS
卷 209, 期 -, 页码 -

出版社

ELSEVIER
DOI: 10.1016/j.comnet.2022.108874

关键词

Distributed Denial of Service (DDoS); Internet of Things (IoT); Botnets; Edge computing; Deep neural networks

向作者/读者索取更多资源

The growing number of IoT edge devices have caused a change in the cyber-attack landscape, particularly with the significant increase in magnitude and intensity of DDoS attacks. This paper proposes a distributed DDoS detection and mitigation framework, SmartDefense, based on edge computing approaches, to detect and mitigate DDoS attacks at and near the source.
The growing number of IoT edge devices have inflicted a change in the cyber-attack space. The DDoS attacks, in particular, have significantly increased in magnitude and intensity. Of the existing DDoS solutions, while the destination-based defense mechanisms incur high false positives due to the seemingly legitimate nature of the attack traffic, defense mechanisms implemented at the source alone do not suffice due to the lack of visibility into ongoing DDoS attacks. This paper proposes a distributed DDoS detection and mitigation framework, SmartDefense, based on edge computing approaches towards detecting and mitigating DDoS attacks at and near the source. By mitigating the DDoS attacks near the source, SmartDefense significantly reduces unnecessary bandwidth otherwise consumed by DDoS traffic going from residential edge networks to the ISP edge network. Furthermore, SmartDefense demonstrates how ISPs can detect botnet devices in their customer's network by having smart edge devices pass attributes that are processed by the botnet detection engine at the provider's edge. The evaluation of this work shows that SmartDefense can improve the detection and mitigation rate, with over 90% of DDoS traffic caught at the source and over 97.5% of remaining DDoS traffic caught at the provider's edge. Our experiments also demonstrate how using a botnet detection engine can further reduce the DDoS traffic by up to 51.95% by facilitating ISPs to detect bot devices in their customers' edge network.

作者

我是这篇论文的作者
点击您的名字以认领此论文并将其添加到您的个人资料中。

评论

主要评分

4.7
评分不足

次要评分

新颖性
-
重要性
-
科学严谨性
-
评价这篇论文

推荐

暂无数据
暂无数据