DNS amplification attack detection and mitigation via sFlow with security-centric SDN

Ahmad Ariff Aizuddin, Mohd Farid Atan, Megat Norulazmi, Megat Norulazmi Megat Mohamed Noor, Shadil Akimi, Zainal Abidin · 2017

Following the rise of modern networking, DDoS attacks are undeniably becoming more abusive. DNS amplification attack is a type of reflected DDoS attack that exploits DNS servers to distribute amplified responses. Detection-wise, related studies have focused on flow-based analysis as the alternative due to its feasibility within high-speed networks. However, fixed flow-monitoring application (i.e. NetFlow) is highly subjected to cache timeout hence lacks the support for a near real-time detection. Mitigation-wise, previous works have concentrated on the use of varying hardware appliances to handle excessive traffic. Nonetheless, such diversities introduce issues regarding flexibility and correlative control thus indicates the absence of centralized/autonomous mitigation. This paper proposed a substitute solution via sFlow with security-centric SDN to timely detect and reasonably mitigate DNS amplification attack.

Read the paper · More papers on PaperTik