Abstract

Distributed Denial of Service (DDoS) attacks constitute a major threat in the current Internet. These cyber-attacks aim to flood the target system with tailored malicious network traffic overwhelming its service capacity and consequently severely limiting legitimate users from using the service. This paper builds on the state-of-the-art AATAC algorithm (Autonomous Algorithm for Traffic Anomaly Detection) and provides a concept of a dedicated inline DDoS detectorcapable of real-time monitoring of network traffic and near-real-time anomaly detection.

The inline DDoS detectorconsists of two main elements: 1) inline probe(s)responsible for link-rate real-time processing and monitoring of network traffic with custom-built packet feature counters, and 2) an analyser that performs the near-real-time statistical analysis of these counters for anomaly detection. These elements communicate asynchronously via the Redis database, facilitating a wide range of deployment scenarios. The inline probes are based on COTS servers and utilise the DPDK framework (Data Plane Development Kit) and parallel packet processing on multiple CPU cores to achieve link rate traffic analysis, including tailored DPI analysis.

Details

Title
On Implementation of Efficient Inline DDoS Detector Based on AATAC Algorithm
Author
Wiśniewski, Piotr; Sosnowski, Maciej; Burakowski, Wojciech
Pages
889-898
Publication year
2022
Publication date
2022
Publisher
Polish Academy of Sciences
ISSN
20818491
e-ISSN
23001933
Source type
Scholarly Journal
Language of publication
English
ProQuest document ID
2831290641
Copyright
© 2022. This work is licensed under https://creativecommons.org/licenses/by-sa/4.0/ (the “License”). Notwithstanding the ProQuest Terms and Conditions, you may use this content in accordance with the terms of the License.