A Defense Strategy Against LDDoS Attack Aggregation in DCN

Kexin Chen, Hang Wang, Peilin Hong · 2023

Multi-tenancy and the vulnerabilities of network isolation make Low-Rate Distributed Denial-of-Service (LDDoS) severe threats to cloud data centers. Due to the stealthy nature of the LDDoS attack, it is not easy to detect in data center networks (DCN) with frequent Incast traffic. And the traditional Detect-Drop defense strategy may drop some benign flows, significantly reducing user experience. To this end, this paper first proposes a mathematical model that reveals the attack aggregation mechanism and queuing pattern of LDDoS attack in DCN. On this basis, this article proposes a novel defense strategy that can interfere with LDDoS attack aggregation without breaking the benign user's connection. When there is an attack detected, the information of normal and suspicious flows will be roughly grouped and notified to the preceding switch, where they will enter different switch queues separately. Afterward, the packets in the suspicious flow queue will be added with a subtle delay when dequeuing. As for the attack flows, it directly results in the inability to aggregate into large pulses. For the normal flow, it merely increases the flow completion time (FCT) by a few microseconds. It is due to this property that the method proposed can defend against attacks without affecting the connection of the normal flows. The simulation results are consistent with the theoretical analysis and show that this strategy can effectively recover the network performance. Moreover, it achieves excellent robustness at low detection accuracy, making it suitable for running in DCN.

Read the paper · More papers on PaperTik