Visible to the public Queue Allocation-Based DDoS Mitigation at Edge Switch

TitleQueue Allocation-Based DDoS Mitigation at Edge Switch
Publication TypeConference Paper
Year of Publication2021
AuthorsYaegashi, Ryo, Hisano, Daisuke, Nakayama, Yu
Conference Name2021 IEEE International Conference on Communications Workshops (ICC Workshops)
Date PublishedJune 2021
PublisherIEEE
ISBN Number978-1-7281-9441-7
KeywordsCommunication system security, composability, computer network management, Computer simulation, Conferences, DDoS attack mitigation, denial-of-service attack, Human Behavior, Image edge detection, Internet of Things, machine learning algorithms, Market research, Metrics, pubcrawl, Queueing analysis, resilience, Resiliency, Switches
Abstract

It has been a hot research topic to detect and mitigate Distributed Denial-of-Service (DDoS) attacks due to the significant increase of serious threat of such attacks. The rapid growth of Internet of Things (IoT) has intensified this trend, e.g. the Mirai botnet and variants. To address this issue, a light-weight DDoS mitigation mechanism was presented. In the proposed scheme, flooding attacks are detected by stochastic queue allocation which can be executed with widespread and inexpensive commercial products at a network edge. However, the detection process is delayed when the number of incoming flows is large because of the randomness of queue allocation. Thus, in this paper we propose an efficient queue allocation algorithm for rapid DDoS mitigation using limited resources. The idea behind the proposed scheme is to avoid duplicate allocation by decreasing the randomness of the existing scheme. The performance of the proposed scheme was confirmed via theoretical analysis and computer simulation. As a result, it was confirmed that malicious flows are efficiently detected and discarded with the proposed algorithm.

URLhttps://ieeexplore.ieee.org/document/9473582
DOI10.1109/ICCWorkshops50388.2021.9473582
Citation Keyyaegashi_queue_2021