DDoS Detection at the Scale of One Hundred Tbps
Yunming Xiao, Xijun Luo, Youliang Jiang, Aike Wang, Hu Chen, Zhibin Zhou, Heng Yu, Jiahao Cao, Yong Jiang, Jilong Wang, Mingwei Xu, Yan Chen, Congcong Miao
摘要
Defending against Distributed Denial-of-Service (DDoS) attacks is a critical priority for cloud providers, who must manage ever-growing volumes of both benign and malicious traffic. While state-of-the-art DDoS detection systems leverage programmable devices to process traffic at hundreds of Gbps to Tbps on a single machine, large-scale cloud providers often handle traffic at scales approaching 100 Tbps. This twoorders-of-magnitude difference necessitates distributed processing across multiple servers, where new challenges are present. Specifically, naive load-balancing strategies lead to imbalanced traffic distribution and severe performance bottlenecks, while function offloading to programmable devices must balance flexibility and adaptability. In this paper, we present Canopy, a scalable DDoS detection system designed to overcome these challenges. Canopy features a dynamic load-balancing mechanism that adapts to fluctuating traffic patterns, ensuring balanced distribution across detection servers despite the mix of mice and elephant flows. Additionally, it employs a traffic compression technique at the programmable switch to significantly reduce per-server workload. These innovations enable Canopy to scale to over 100 Tbps in real-world deployments. Successfully deployed in production, Canopy has demonstrated its effectiveness in mitigating large-scale DDoS attacks.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它它引用的顶会 Paper14
- Jaqen: A High-Performance Switch-Native Approach for Detecting and Mitigating Volumetric DDoS Attacks with Programmable SwitchesZaoxing Liu, Hun Namkung, Georgios Nikolaidis, Jeongkeun Lee 等USENIX Security 2021 · 被引用 221 次
- Freezing the Web: A Study of ReDoS Vulnerabilities in JavaScript-based Web ServersCristian-Alexandru Staicu, Michael PradelUSENIX Security 2018 · 被引用 125 次
- PLB: congestion signals are simple and effective for network load balancingMubashir Adnan Qureshi, Yuchung Cheng, Qianwen Yin, Qiaobin Fu 等SIGCOMM 2022 · 被引用 82 次
- Aggregate-based congestion control for pulse-wave DDoS defenseAlbert Gran Alcoz, Martin Strohmeier, Vincent Lenders, Laurent VanbeverSIGCOMM 2022 · 被引用 63 次
- Achieving 100Gbps Intrusion Prevention on a Single ServerZhipeng Zhao, Hugo Sadok, Nirav Atre, James C. Hoe 等OSDI 2020 · 被引用 38 次
相关 Paper
- Excalibur: A Scalable and Low-Cost Traffic Testing Framework for Evaluating DDoS Defense SolutionsXiang Chen, Hongyan Liu, Tingxin Sun, Qun Huang 等INFOCOM 2023 · 被引用 3 次
- Leveraging Prefix Structure to Detect Volumetric DDoS Attack Signatures with Programmable SwitchesChris Misa, Ramakrishnan Durairajan, Arpit Gupta, Reza Rejaie 等S&P 2024 · 被引用 7 次
- Lemon: Network-Wide DDoS Detection with Routing-Oblivious Per-Flow MeasurementWenhao Wu, Zhenyu Li, Xilai Liu, Zhaohua Wang 等USENIX Security 2025
- MiddlePolice: Toward Enforcing Destination-Defined Policies in the Middle of the InternetZhuotao Liu, Hao Jin, Yih-Chun Hu, Michael D. BaileyCCS 2016 · 被引用 52 次
- Cost-effective and Reliable Global Internet Peering with Programmable SwitchesCongcong Miao, Zhiyi Yao, Jianchao Lv, Jinglin Wang 等NSDI 2026 · 被引用 2 次
