Efficient DDoS Detection and Mitigation in Cloud Data Centers Using eBPF and XDP
Ziyue Chen, He Kong, Shuai Ding, Quanfeng Lv, Guo Wei · 2024
With the widespread adoption of cloud-native architectures, data centers are increasingly facing severe security challenges, particularly in defending against distributed denial-of-service (DDoS) attacks. The complex interdependencies between microservices allow the impact of a DDoS attack to spread rapidly, significantly degrading overall server performance. Traditional DDoS defense strategies often struggle to effectively counter attacks within data centers, particularly those targeting east-west traffic. To address this issue, this paper proposes a fast and efficient DDoS detection and mitigation mechanism specifically tailored for data center environments using extended Berkeley Packet Filter (eBPF) and eXpress Data Path (XDP) technologies. By leveraging eBPF, we achieve kernel-level, nonintrusive data collection while maintaining flow state tracking, thereby reducing communication overhead. Additionally, we trained an XGBoost classification model to create DDoS traffic filtering rules specifically designed for data center scenarios. Combined with XDP technology, we implemented low-latency malicious traffic detection at the entry point of the network protocol stack, allowing for the immediate filtering of attack traffic and thereby mitigating the impact of DDoS attacks. Experimental results demonstrate that, compared to traditional tools, our approach not only achieves high accuracy but also significantly enhances system performance.