Leveraging Prefix Structure to Detect Volumetric DDoS Attack Signatures with Programmable Switches
Chris Misa, Ramakrishnan Durairajan, Arpit Gupta, Reza Rejaie, Walter Willinger
Abstract
As increasingly complex and dynamic volumetric DDoS attacks continue to wreak havoc on edge networks, two recent developments promise to bolster DDoS defense at the edge. First, programmable switches have emerged as promising means for achieving scalable and cost-effective attack signature detection. However, their practical application in edge networks remains a challenging open problem. Second, machine learning (ML)-based solutions have demonstrated potential in accurately detecting attack signatures based on per-flow traffic features. Yet, their inability to effectively scale to the traffic volumes and number of flows in actual production edge networks has largely excluded them from practical considerations.In this paper, we introduce ZAPDOS, a novel approach to accurately, quickly, and scalably detect volumetric DDoS attack signatures at the source prefix level. ZAPDOS is the first to utilize a key characteristic of the observed structure of measured attack and benign source prefixes (i.e., a pronounced cluster-within-cluster property) and effectively apply it in practice against modern attacks. ZAPDOS operates by monitoring aggregate prefix-level features in switch hardware, employing a learning model to identify prefixes suspected of containing attack sources, and using several innovative algorithmic methods to pinpoint attack sources efficiently. We have built a hardware prototype of ZAPDOS and a packet-level software simulator which achieve comparable accuracy results. Since existing datasets are inadequate for training and evaluating prefix-level models, we have developed a new data-fusion methodology for training and evaluating ZAPDOS. We use our prototype and simulator to show that ZAPDOS can detect volumetric DDoS attack signatures with orders of magnitude lower error rates than state-of-the-art under comparable monitoring resource budgets and for a range of different attack scenarios.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 07afe61b-d7d6-4d30-9e1b-d2e6a8b1a878Cited by top-tier papers2
- When Address Learning Goes Wrong: Inducing Forwarding Loops and DoS Amplification in SDNDezhang Kong, Yilun Zhang, Zekun Xie, Ningpeng Zheng et al.USENIX Security 2026
- Defeating Slow-and-Low Threats via Diffusion Model-based Generative InferenceSeyed Mohammad Mehdi Mirnajafizadeh, Prashant Khanduri, DaeHun Nyang, Rhongho JangNSDI 2026
Builds on14
- Jaqen: A High-Performance Switch-Native Approach for Detecting and Mitigating Volumetric DDoS Attacks with Programmable SwitchesZaoxing Liu, Hun Namkung, Georgios Nikolaidis, Jeongkeun Lee et al.USENIX Security 2021 · 221 citations
- SPIFFY: Inducing Cost-Detectability Tradeoffs for Persistent Link-Flooding AttacksMin Suk Kang, Virgil D. Gligor, Vyas SekarNDSS 2016 · 123 citations
- Ripple: A Programmable, Decentralized Link-Flooding Defense Against Adaptive AdversariesJiarong Xing, Wenqing Wu, Ang ChenUSENIX Security 2021 · 100 citations
- Taurus: a data plane architecture for per-packet MLTushar Swamy, Alexander Rucker, Muhammad Shahbaz, Ishan Gaur et al.ASPLOS 2022 · 94 citations
- Mousika: Enable General In-Network Intelligence in Programmable Switches by Knowledge DistillationGuorui Xie, Qing Li, Yutao Dong, Guanglin Duan et al.INFOCOM 2022 · 83 citations
Related papers
- Lemon: Network-Wide DDoS Detection with Routing-Oblivious Per-Flow MeasurementWenhao Wu, Zhenyu Li, Xilai Liu, Zhaohua Wang et al.USENIX Security 2025
- Aggregate-based congestion control for pulse-wave DDoS defenseAlbert Gran Alcoz, Martin Strohmeier, Vincent Lenders, Laurent VanbeverSIGCOMM 2022 · 63 citations
- SISTAR: An Efficient DDoS Detection and Mitigation Framework Utilizing Programmable Data PlanesJunjie Hu, Feng Guo, Qihang Zhou, Yixin Zhang et al.CCS 2025
- DDoS Detection at the Scale of One Hundred TbpsYunming Xiao, Xijun Luo, Youliang Jiang, Aike Wang et al.NSDI 2026 · 2 citations
- Mew: Enabling Large-Scale and Dynamic Link-Flooding Defenses on Programmable SwitchesHuancheng Zhou, Sungmin Hong, Yangyang Liu, Xiapu Luo et al.S&P 2023
