Low-reaction time FPGA-based DDoS detector

Balázs Nagy, Péter Orosz, Pál Varga · 2018

While Distributed Denial of Service (DDoS) attacks are among the most investigated and documented cyber threats, their mitigation is still not solved. The latest generation of DDoS threats requires a different protection scheme. Current widespread Intrusion Prevention Systems (IPS) have a reaction time in the range of seconds and minutes. However, hit-and- run type of attacks, that last only a few tens or hundreds of milliseconds, are therefore often invisible for these security systems. We have developed a set of DDoS detection methods to identify the Top-9 Akamai threat types that cover more than 96% of DDoS attacks globally. As proof-of-concept (PoC), we designed and implemented a detection engine incorporating these methods in a 100 Gbps packet processing FPGA platform. The PoC system identifies the specified attacks within milliseconds. The short detection time also enables preventing hit-and-run attacks, which deliver high intensity malicious traffic over a short period of time. We have validated our system with real-life as well as synthesized DDoS attacks. The real DDoS traces were captured in a medium-sized datacenter network. In this demonstration, we are going to showcase the effectiveness of the detector engine in various security scenarios.

Read the paper · More papers on PaperTik