DDoS Detection at the Scale of One Hundred Tbps
Yunming Xiao, Xijun Luo, Youliang Jiang, Aike Wang, Hu Chen, Zhibin Zhou, Heng Yu, Jiahao Cao, Yong Jiang, Jilong Wang, Mingwei Xu, Yan Chen, Congcong Miao
Abstract
Defending against Distributed Denial-of-Service (DDoS) attacks is a critical priority for cloud providers, who must manage ever-growing volumes of both benign and malicious traffic. While state-of-the-art DDoS detection systems leverage programmable devices to process traffic at hundreds of Gbps to Tbps on a single machine, large-scale cloud providers often handle traffic at scales approaching 100 Tbps. This twoorders-of-magnitude difference necessitates distributed processing across multiple servers, where new challenges are present. Specifically, naive load-balancing strategies lead to imbalanced traffic distribution and severe performance bottlenecks, while function offloading to programmable devices must balance flexibility and adaptability. In this paper, we present Canopy, a scalable DDoS detection system designed to overcome these challenges. Canopy features a dynamic load-balancing mechanism that adapts to fluctuating traffic patterns, ensuring balanced distribution across detection servers despite the mix of mice and elephant flows. Additionally, it employs a traffic compression technique at the programmable switch to significantly reduce per-server workload. These innovations enable Canopy to scale to over 100 Tbps in real-world deployments. Successfully deployed in production, Canopy has demonstrated its effectiveness in mitigating large-scale DDoS attacks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 329a8fbb-cbe9-4f1c-96fc-847d242d1d4bCited by top-tier papers1
Ask how each one uses itBuilds on14
- Jaqen: A High-Performance Switch-Native Approach for Detecting and Mitigating Volumetric DDoS Attacks with Programmable SwitchesZaoxing Liu, Hun Namkung, Georgios Nikolaidis, Jeongkeun Lee et al.USENIX Security 2021 · 221 citations
- Freezing the Web: A Study of ReDoS Vulnerabilities in JavaScript-based Web ServersCristian-Alexandru Staicu, Michael PradelUSENIX Security 2018 · 125 citations
- PLB: congestion signals are simple and effective for network load balancingMubashir Adnan Qureshi, Yuchung Cheng, Qianwen Yin, Qiaobin Fu et al.SIGCOMM 2022 · 82 citations
- Aggregate-based congestion control for pulse-wave DDoS defenseAlbert Gran Alcoz, Martin Strohmeier, Vincent Lenders, Laurent VanbeverSIGCOMM 2022 · 63 citations
- Achieving 100Gbps Intrusion Prevention on a Single ServerZhipeng Zhao, Hugo Sadok, Nirav Atre, James C. Hoe et al.OSDI 2020 · 38 citations
Related papers
- Excalibur: A Scalable and Low-Cost Traffic Testing Framework for Evaluating DDoS Defense SolutionsXiang Chen, Hongyan Liu, Tingxin Sun, Qun Huang et al.INFOCOM 2023 · 3 citations
- Leveraging Prefix Structure to Detect Volumetric DDoS Attack Signatures with Programmable SwitchesChris Misa, Ramakrishnan Durairajan, Arpit Gupta, Reza Rejaie et al.S&P 2024 · 7 citations
- Lemon: Network-Wide DDoS Detection with Routing-Oblivious Per-Flow MeasurementWenhao Wu, Zhenyu Li, Xilai Liu, Zhaohua Wang et al.USENIX Security 2025
- MiddlePolice: Toward Enforcing Destination-Defined Policies in the Middle of the InternetZhuotao Liu, Hao Jin, Yih-Chun Hu, Michael D. BaileyCCS 2016 · 52 citations
- Cost-effective and Reliable Global Internet Peering with Programmable SwitchesCongcong Miao, Zhiyi Yao, Jianchao Lv, Jinglin Wang et al.NSDI 2026 · 2 citations
