STONE: A stream-based DDoS defense framework

Mar Callau-Zori ; Vincenzo Gulisano ; Zhang Fu (Institutionen för data- och informationsteknik, Nätverk och system (Chalmers) ) ; Ricardo Jiménez-Péris ; Marina Papatriantafilou (Institutionen för data- och informationsteknik, Nätverk och system (Chalmers) ) ; Marta Patiño-Martínez
Proceedings of the ACM Symposium on Applied Computing, SAC 2013; Coimbra; Portugal; 18 March 2013 through 22 March 2013 p. 807-812. (2013)
[Konferensbidrag, refereegranskat]

An effective Distributed Denial of Service (DDoS) defense mechanism must guarantee legitimate users access to an Internet service masking the effects of possible attacks. That is, it must be able to detect threats and discard malicious packets in a online fashion. Given that emerging data streaming technology can enable such mitigation in an effective manner, in this paper we present STONE, a stream-based DDoS defense framework, which integrates anomaly-based DDoS detection and mitigation with scalable data streaming technology. With STONE, the traffic of potential targets is analyzed via continuous data streaming queries maintaining information used for both attack detection and mitigation. STONE provides minimal degradation of legitimate users traffic during DDoS attacks and it also faces effectively flash crowds. Our preliminary evaluation based on an implemented prototype and conducted with real legitimate and malicious traffic traces shows that STONE is able to provide fast detection and precise mitigation of DDoS attacks leveraging scalable data streaming technology.

Nyckelord: Data streaming, DDoS detection and mitigation

