TSA: A Two-Phase Scheme Against Amplification DDoS Attack in SDN.

Zheng Liu,Mingwei Xu,Jiahao Cao,Qi Li
DOI: https://doi.org/10.1007/978-981-10-8890-2_37
2018-01-01
Abstract:Amplification attack, as a new kind of DDoS attack, is more destructive than traditional DDoS attack. Under the existing Internet architecture, it is difficult to find effective measures to deal with amplification attack. In this paper, we propose a two-phase reference detecting scheme by utilizing Software Defined Infrastructure capabilities: switch side is volume-based and controller side is feature-based. The proposed scheme is protocol-independent and lightweight, unlike most of the existing strategies. It can also detect amplification attack in the request phase for a small price, before these attacks cause actual harm. Upon the architecture, we design detection algorithms and a prototype system. Experimental results with both online and offline data sets show that the detection scheme is effective and efficient.
What problem does this paper attempt to address?