2019
DOI: 10.1109/access.2019.2933491
|View full text |Cite
|
Sign up to set email alerts
|

Introducing SmartNICs in Server-Based Data Plane Processing: The DDoS Mitigation Use Case

Abstract: In the recent years, the complexity of the network data plane and their requirements in terms of agility has increased significantly, with many network functions now implemented in software and executed directly in datacenter servers. To avoid bottlenecks and to keep up with the ever increasing network speeds, recent approaches propose to move the software packet processing in kernel space using technologies such as eBPF/XDP, or to offload (part of it) in specialized hardware, the so called SmartNICs. This pap… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

2
19
0
2

Year Published

2020
2020
2022
2022

Publication Types

Select...
7
1

Relationship

2
6

Authors

Journals

citations
Cited by 40 publications
(23 citation statements)
references
References 18 publications
2
19
0
2
Order By: Relevance
“…However, in contrast to cloud highperformance servers, edge nodes cannot exploit sophisticated solutions against DDoS attacks, due to their limited computing and memory resources. Although recent research efforts have demonstrated that the mitigation of DDoS attacks is feasible even by means of commodity computers [72], [73], edge computing-based DDoS detection is still at an early stage.…”
Section: Use-case: Ddos Detection At the Edgementioning
confidence: 99%
“…However, in contrast to cloud highperformance servers, edge nodes cannot exploit sophisticated solutions against DDoS attacks, due to their limited computing and memory resources. Although recent research efforts have demonstrated that the mitigation of DDoS attacks is feasible even by means of commodity computers [72], [73], edge computing-based DDoS detection is still at an early stage.…”
Section: Use-case: Ddos Detection At the Edgementioning
confidence: 99%
“…The virtualization overhead, the utilization level of the servers and the techniques adopted to implement the VSNFs are the most significant contributors to the performance degradation. To mitigate the problem, recent approaches propose to either adopt kernel bypass technologies such as the Data Plane Development Kit (DPDK) [122], Netmap [123] or Vectorized Packet Processing (VPP) [124], or to move the software packet processing in kernel space using eBPF/XDP [125].…”
Section: Threat Detection and Mitigationmentioning
confidence: 99%
“…eBPF programs can be attached even before packet enter PREROUTING chain of Netfilter. eBPF based program XDP provides possibility to process packets before TCP/IP stack achieving higher performance of packet processing (Miano et al, 2019b). Location of Netfilter's chains, most popular tables and eBPF hooks are shown in Figure 1.…”
Section: Packet Flow In Netfilter and Ebpfmentioning
confidence: 99%