FlowSentry: Accelerating NetFlow-based DDoS Detection
Xiaoyu He, Xiaohui Xie, Xin Wang, Lei Zhang, Kun Xie, Lin Chen, Yong Cui
Abstract
Distributed Denial of Service (DDoS) attacks threaten the stability of online services by overwhelming them with excessive traffic. NetFlow-based DDoS detection systems are widely adopted by Internet Service Providers (ISPs) in upstream multi-point detection scenarios to provide robust detection for volumetric DDoS attacks. However, these systems face inherent delays, as NetFlow detection is non-instantaneous—routers aggregate and summarize flow records over a period before reporting, which impacts timely detection. Existing research primarily focuses on optimizing the NetFlow reporting mechanism at the router side. Unfortunately, the need for either software or hardware upgrades for routers would incur a high deployment cost, which is impractical for ISPs in the short term. In this paper, we propose FlowSentry, a novel NetFlow detection framework to accelerate DDoS attack identification at the server side. The system operates on a dual-layer filtering paradigm to handle the high-frequency NetFlow records, incorporating two core technologies: ADWindow and STAnalyzer. ADWindow is a sketch-based sliding window mechanism designed to retain possibly anomalous flow information, filtering out benign flows to reduce the computational overhead. STAnalyzer leverages the cross-router traffic correlation to efficiently infer abnormal growth patterns of potential malicious traffic based on partially reported flow records, thus significantly reducing the detection delay. Our extensive experiments in simulated backbone network environments demonstrate that FlowSentry achieves better detection accuracy while reducing the detection delay by up to 65.63% compared to existing methods.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Related papers
- NetRadar: Enabling Robust Carpet Bombing DDoS DetectionJunchen Pan, Lei Zhang, Xiaoyong Si, Jie Zhang et al.NDSS 2026 · 1 citation
- IPD: Detecting Traffic Ingress Points at ISPsStefan Mehner, Helge Reelfs, Ingmar Poese, Oliver HohlfeldSIGCOMM 2024 · 1 citation
- FD-Filter: A Compact Data Structure for Fine-Grained Intra-Flow Packet Delay MonitoringJintao He, Jie Gui, Tian Lv, Jiaqi Zhu et al.INFOCOM 2025 · 1 citation
- Lemon: Network-Wide DDoS Detection with Routing-Oblivious Per-Flow MeasurementWenhao Wu, Zhenyu Li, Xilai Liu, Zhaohua Wang et al.USENIX Security 2025
- NetSynergy: Mitigating Application-layer DDoS via Adaptive Access-Backbone CollaborationJunchen Pan, Kunpeng He, Shengnan Liu, Menghao Zhang et al.CCS 2026
