Credible Link Flooding Attack Detection and Mitigation: A Blockchain-Based Approach

Xiaofeng Jiang,Qianbao Shi,Hengkun Miao,Wanqin Cao,Huasen He,Shuangwu Chen,Jian Yang
DOI: https://doi.org/10.1109/tnsm.2024.3357660
2024-01-01
IEEE Transactions on Network and Service Management
Abstract:Due to the concentrated distribution of network traffic, the Internet is highly vulnerable to link flooding attack in Distributed Denial-of-Service attacks (DDoS-LFA), which utilizes the legitimate low-rate attack traffic to block the selected network area. In recent years, building trusted networks has been considered as a promising strategy to address the security issues. Nevertheless, deploying a trusted link defense mechanism in the attacked network area faces many challenges imposed by the smart scheme and legitimate disguise of DDoS-LFA. In order to overcome these challenges, we propose a blockchain-based DDoS-LFA detection and mitigation scheme, named CREDIT, to guarantee the security of attacked area, while existing works only use blockchain to share the detection results of traditional solutions. CREDIT uses blockchain to record and share the information of links and flows in real time, which enables routers in the protected area to easily trace the paths of all active flows and capture the fragile links. On the basis of link features, a credible deep learning method performed on randomly selected nodes is proposed to detect DDoS-LFA against data spoofing. When an attack alarm is raised, CREDIT performs similarity analysis to locate attackers and migrate suspicious traffic based on the flow features of alarm links. Experimental results based on real implementation and attack testbed show that, by integrating blockchain, CREDIT performs better than traditional non-blockchain-based DDoS-LFA defense methods when faced with data tampering.
What problem does this paper attempt to address?