论文标题
资源有限的网络边缘减轻轻量DDOS
Light-Weight DDoS Mitigation at Network Edge with Limited Resources
论文作者
论文摘要
近年来,物联网(物联网)一直在迅速增长。随着5G的出现,预计它对人们的生活变得更加必不可少。根据IoT设备的分布式拒绝服务(DDOS)攻击的增加,DDOS防御已成为热门研究主题。已经深入研究了在路由器和SDN环境上执行的DDOS检测机制。但是,这些方法的缺点是需要设备的成本和性能。此外,网络边缘上没有现有的DDOS缓解算法,可以使用低成本和低性能设备执行。因此,本文建议使用廉价设备(例如Home Gateways)的有限资源在网络边缘进行轻型DDOS缓解方案。拟议计划的目的是简单地检测和减轻洪水攻击。它利用未使用的队列资源来检测恶意流,通过随机改组队列分配并丢弃检测到的流量的数据包。通过理论分析和计算机模拟确认了所提出的方案的性能。模拟结果与理论结果相匹配,并且提出的算法可以使用有限的资源有效地检测出恶意流。
The Internet of Things (IoT) has been growing rapidly in recent years. With the appearance of 5G, it is expected to become even more indispensable to people's lives. In accordance with the increase of Distributed Denial-of-Service (DDoS) attacks from IoT devices, DDoS defense has become a hot research topic. DDoS detection mechanisms executed on routers and SDN environments have been intensely studied. However, these methods have the disadvantage of requiring the cost and performance of the devices. In addition, there is no existing DDoS mitigation algorithm on the network edge that can be performed with the low-cost and low performance equipments. Therefore, this paper proposes a light-weight DDoS mitigation scheme at the network edge using limited resources of inexpensive devices such as home gateways. The goal of the proposed scheme is to simply detect and mitigate flooding attacks. It utilizes unused queue resources to detect malicious flows by random shuffling of queue allocation and discard the packets of the detected flows. The performance of the proposed scheme was confirmed via theoretical analysis and computer simulation. The simulation results match the theoretical results and the proposed algorithm can efficiently detect malicious flows using limited resources.