Aggregate-based congestion control for pulse-wave DDoS defense
Albert Gran Alcoz, Martin Strohmeier, Vincent Lenders, Laurent Vanbever
Abstract
Pulse-wave DDoS attacks are a new type of volumetric attack formed by short, high-rate traffic pulses. Such attacks target the Achilles' heel of state-of-the-art DDoS defenses: their reaction time. By continuously adapting their attack vectors, pulse-wave attacks manage to render existing defenses ineffective.
In this paper, we leverage programmable switches to build an in-network DDoS defense effective against pulse-wave attacks. To do so, we revisit Aggregate-based Congestion Control (ACC): a mechanism proposed two decades ago to manage congestion events caused by high-bandwidth traffic aggregates. While ACC proved efficient in inferring and controlling DDoS attacks, it cannot keep up with the speed requirements of pulse-wave attacks.
We propose ACC-Turbo, a renewed version of ACC that infers attack patterns by applying online-clustering techniques in the network and mitigates them by leveraging programmable packet scheduling. By doing so, ACC-Turbo identifies attacks at line rate and in real-time, and rate-limits attack traffic on a per-packet basis.
We fully implement ACC-Turbo in P4 and evaluate it on a wide range of attack scenarios. Our evaluation shows that ACC-Turbo autonomously identifies DDoS attack vectors in an unsupervised manner and rapidly mitigates pulse-wave DDoS attacks. We also show that ACC-Turbo runs on existing hardware (Intel Tofino).
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext f4af709e-6825-4695-af2c-65f0ce6b60b3Cited by top-tier papers19
- SmartCookie: Blocking Large-Scale SYN Floods with a Split-Proxy Defense on Programmable Data PlanesSophia Yoo, Xiaoqi Chen, Jennifer RexfordUSENIX Security 2024 · 18 citations
- Detecting Tunneled Flooding Traffic via Deep Semantic Analysis of Packet Length PatternsChuanpu Fu, Qi Li, Meng Shen, Ke XuCCS 2024 · 13 citations
- FENIX: Enabling In-Network DNN Inference with FPGA-Enhanced Programmable SwitchesXiangyu Gao, Tong Li, Yinchao Zhang, Ziqiang Wang et al.NSDI 2026 · 12 citations
- Leveraging Prefix Structure to Detect Volumetric DDoS Attack Signatures with Programmable SwitchesChris Misa, Ramakrishnan Durairajan, Arpit Gupta, Reza Rejaie et al.S&P 2024 · 7 citations
- Zero-setup Intermediate-rate Communication Guarantees in a Global InternetMarc Wyss, Adrian PerrigUSENIX Security 2024 · 3 citations
Builds on10
- Understanding the Mirai BotnetManos Antonakakis, Tim April, Michael D. Bailey, Matt Bernhard et al.USENIX Security 2017 · 2,003 citations
- Kitsune: An Ensemble of Autoencoders for Online Network Intrusion DetectionYisroel Mirsky, Tomer Doitshman, Yuval Elovici, Asaf ShabtaiNDSS 2018 · 945 citations
- Jaqen: A High-Performance Switch-Native Approach for Detecting and Mitigating Volumetric DDoS Attacks with Programmable SwitchesZaoxing Liu, Hun Namkung, Georgios Nikolaidis, Jeongkeun Lee et al.USENIX Security 2021 · 221 citations
- SP-PIFO: Approximating Push-In First-Out Behaviors using Strict-Priority QueuesAlbert Gran Alcoz, Alexander Dietmüller, Laurent VanbeverNSDI 2020 · 140 citations
- SPIFFY: Inducing Cost-Detectability Tradeoffs for Persistent Link-Flooding AttacksMin Suk Kang, Virgil D. Gligor, Vyas SekarNDSS 2016 · 123 citations
Related papers
- Mew: Enabling Large-Scale and Dynamic Link-Flooding Defenses on Programmable SwitchesHuancheng Zhou, Sungmin Hong, Yangyang Liu, Xiapu Luo et al.S&P 2023
- Poseidon: Mitigating Volumetric DDoS Attacks with Programmable SwitchesMenghao Zhang, Guanyu Li, Shicheng Wang, Chang Liu et al.NDSS 2020
- P4Control: Line-Rate Cross-Host Attack Prevention via In-Network Information Flow Control Enabled by Programmable Switches and eBPFOsama Bajaber, Bo Ji, Peng GaoS&P 2024 · 11 citations
- On the Security Risks of Memory Adaptation and Augmentation in Data-plane DoS MitigationHocheol Nam, Daehyun Lim, Huancheng Zhou, Guofei Gu et al.NDSS 2026
- ReAct: Reflection Attack Mitigation For Asymmetric RoutingDavid Hay, Mary Hogan, Shir Landau FeibishINFOCOM 2026 · 1 citation
