2022
DOI: 10.1109/tdsc.2021.3116345
|View full text |Cite
|
Sign up to set email alerts
|

Tracking Normalized Network Traffic Entropy to Detect DDoS Attacks in P4

Abstract: Distributed Denial-of-Service (DDoS) attacks represent a persistent threat to modern telecommunications networks: detecting and counteracting them is still a crucial unresolved challenge for network operators. DDoS attack detection is usually carried out in one or more central nodes that collect significant amounts of monitoring data from networking devices, potentially creating issues related to network overload or delay in detection. The dawn of programmable data planes in Software-Defined Networks can help … Show more

Help me understand this report
View preprint versions

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
10
0

Year Published

2023
2023
2024
2024

Publication Types

Select...
4
2

Relationship

0
6

Authors

Journals

citations
Cited by 24 publications
(10 citation statements)
references
References 31 publications
0
10
0
Order By: Relevance
“…However, the widely adopted data plane programming language, P4, lacks support for many arithmetic operations, limiting the straightforward implementation of advanced network monitoring functionalities required for DDoS detection. To address this limitation, Ding et al [7] present two novel strategies for flow cardinality and normalized network traffic entropy estimation, which rely solely on P4-supported operations and ensure low relative error. Building upon these contributions, the authors propose a DDoS detection strategy based on variations of normalized network traffic entropy.…”
Section: Related Workmentioning
confidence: 99%
See 4 more Smart Citations
“…However, the widely adopted data plane programming language, P4, lacks support for many arithmetic operations, limiting the straightforward implementation of advanced network monitoring functionalities required for DDoS detection. To address this limitation, Ding et al [7] present two novel strategies for flow cardinality and normalized network traffic entropy estimation, which rely solely on P4-supported operations and ensure low relative error. Building upon these contributions, the authors propose a DDoS detection strategy based on variations of normalized network traffic entropy.…”
Section: Related Workmentioning
confidence: 99%
“…The PoC illustrates how GRAPH4 can efficiently enhance network security by providing a holistic view of vulnerabilities and potential attack paths while monitoring and reacting in case of a detected attack. In terms of specific implementation choices, it combines high-level metrics on the controller by generating a MulVal AG to pinpoint the vulnerable hosts and P4NEntropy [7] on the data plane as a low-level metric to calculate the normalized entropy and detect ongoing anomalies.…”
Section: Proof Of Conceptmentioning
confidence: 99%
See 3 more Smart Citations