IXP scrubber: learning from blackholing traffic for ML-driven DDoS detection at scale
Matthias Wichtlhuber, Eric Strehle, Daniel Kopp, Lars Prepens, Stefan Stegmueller, Alina Rubina, Christoph Dietzel, Oliver Hohlfeld
Abstract
Distributed Denial of Service (DDoS) attacks are among the most critical cybersecurity threats, jeopardizing the stability of even the largest networks and services. The existing range of mitigation services predominantly filters at the edge of the Internet, thus creating unnecessary burden for network infrastructures. Consequently, we present IXP Scrubber, a Machine Learning (ML) based system for detecting and filtering DDoS traffic at the core of the Internet at Internet Exchange Points (IXPs) which see large volumes and varieties of DDoS. IXP Scrubber continuously learns DDoS traffic properties from neighboring Autonomous Systems (ASes). It utilizes BGP signals to drop traffic for certain routes (blackholing) to sample DDoS and can thus learn new attack vectors without the operator's intervention and on unprecedented amounts of training data. We present three major contributions: i) a method to semi-automatically generate arbitrarily large amounts of labeled DDoS training data from IXPs' sampled packet traces, ii) the novel, controllable, locally explainable and highly precise two-step IXP Scrubber ML model, and iii) an evaluation of the IXP Scrubber ML model, including its temporal and geographical drift, based on data from 5 IXPs covering a time span of up to two years.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 14b2f6c6-419d-4dbe-890f-382ce09c3f94Cited by top-tier papers4
- Point Cloud Analysis for ML-Based Malicious Traffic Detection: Reducing Majorities of False Positive AlarmsChuanpu Fu, Qi Li, Ke Xu, Jianping WuCCS 2023 · 30 citations
- Detecting Tunneled Flooding Traffic via Deep Semantic Analysis of Packet Length PatternsChuanpu Fu, Qi Li, Meng Shen, Ke XuCCS 2024 · 13 citations
- Leveraging Prefix Structure to Detect Volumetric DDoS Attack Signatures with Programmable SwitchesChris Misa, Ramakrishnan Durairajan, Arpit Gupta, Reza Rejaie et al.S&P 2024 · 7 citations
- MalMoE: Mixture-of-Experts Enhanced Encrypted Malicious Traffic Detection Under Graph DriftYunpeng Tan, Qingyang Li, Mingxin Yang, Yannan Hu et al.INFOCOM 2026 · 1 citation
Builds on4
- Understanding the Mirai BotnetManos Antonakakis, Tim April, Michael D. Bailey, Matt Bernhard et al.USENIX Security 2017 · 2,003 citations
- Cleaning Up the Internet of Evil Things: Real-World Evidence on ISP and Consumer Efforts to Remove MiraiOrçun Çetin, Carlos Gañán, Lisette Altena, Takahiro Kasama et al.NDSS 2019 · 57 citations
- United We Stand: Collaborative Detection and Mitigation of Amplification DDoS Attacks at ScaleDaniel Wagner, Daniel Kopp, Matthias Wichtlhuber, Christoph Dietzel et al.CCS 2021 · 50 citations
- Weaponizing Middleboxes for TCP Reflected AmplificationKevin Bock, Abdulrahman Alaraj, Yair Fax, Kyle Hurley et al.USENIX Security 2021 · 49 citations
Related papers
- Exploiting vulnerabilities at IXP route servers to perform stealth BGP hijacksGabby Rimlinger, Joaquim Pereira, Matthieu Gouel, Olivier Fourmaux et al.CCS 2026
- Routing Around Congestion: Defeating DDoS Attacks and Adverse Network Conditions via Reactive BGP RoutingJared M. Smith, Max SchuchardS&P 2018 · 71 citations
- NetRadar: Enabling Robust Carpet Bombing DDoS DetectionJunchen Pan, Lei Zhang, Xiaoyong Si, Jie Zhang et al.NDSS 2026 · 1 citation
- Runtime Recovery of Web Applications under Zero-Day ReDoS AttacksZhihao Bai, Ke Wang, Hang Zhu, Yinzhi Cao et al.S&P 2021 · 19 citations
- A System to Detect Forged-Origin BGP HijacksThomas Holterbach, Thomas Alfroy, Amreesh Phokeer, Alberto Dainotti et al.NSDI 2024 · 21 citations
