Queue Allocation-Based DDoS Mitigation at Edge Switch
Title | Queue Allocation-Based DDoS Mitigation at Edge Switch |
Publication Type | Conference Paper |
Year of Publication | 2021 |
Authors | Yaegashi, Ryo, Hisano, Daisuke, Nakayama, Yu |
Conference Name | 2021 IEEE International Conference on Communications Workshops (ICC Workshops) |
Date Published | June 2021 |
Publisher | IEEE |
ISBN Number | 978-1-7281-9441-7 |
Keywords | Communication system security, composability, computer network management, Computer simulation, Conferences, DDoS attack mitigation, denial-of-service attack, Human Behavior, Image edge detection, Internet of Things, machine learning algorithms, Market research, Metrics, pubcrawl, Queueing analysis, resilience, Resiliency, Switches |
Abstract | It has been a hot research topic to detect and mitigate Distributed Denial-of-Service (DDoS) attacks due to the significant increase of serious threat of such attacks. The rapid growth of Internet of Things (IoT) has intensified this trend, e.g. the Mirai botnet and variants. To address this issue, a light-weight DDoS mitigation mechanism was presented. In the proposed scheme, flooding attacks are detected by stochastic queue allocation which can be executed with widespread and inexpensive commercial products at a network edge. However, the detection process is delayed when the number of incoming flows is large because of the randomness of queue allocation. Thus, in this paper we propose an efficient queue allocation algorithm for rapid DDoS mitigation using limited resources. The idea behind the proposed scheme is to avoid duplicate allocation by decreasing the randomness of the existing scheme. The performance of the proposed scheme was confirmed via theoretical analysis and computer simulation. As a result, it was confirmed that malicious flows are efficiently detected and discarded with the proposed algorithm. |
URL | https://ieeexplore.ieee.org/document/9473582 |
DOI | 10.1109/ICCWorkshops50388.2021.9473582 |
Citation Key | yaegashi_queue_2021 |
- Internet of Things
- Switches
- Resiliency
- resilience
- Queueing analysis
- pubcrawl
- Metrics
- Market research
- machine learning algorithms
- Communication system security
- Image edge detection
- Human behavior
- denial-of-service attack
- DDoS attack mitigation
- Conferences
- Computer simulation
- computer network management
- composability