SmartCookie: Blocking Large-Scale SYN Floods with a Split-Proxy Defense on Programmable Data Planes
Sophia Yoo, Xiaoqi Chen, Jennifer Rexford
摘要
Despite decades of mitigation efforts, SYN flooding attacks continue to increase in frequency and scale, and adaptive adversaries continue to evolve. Meanwhile, volumes of benign traffic in modern networks are also growing rampantly. As a result, network providers, which run thousands of servers and process 100s of Gbps of traffic, find themselves urgently requiring defenses that are secure against adaptive adversaries, scalable against large volumes of traffic, and highly performant for benign applications. Unfortunately, existing defenses local to a single device (e.g., purely software-based or hardware-based) are failing to keep up with growing attacks and struggle to provide performance, security, or both. In this paper, we present SMARTCOOKIE, the first system to run cryptographically secure SYN cookie checks on highspeed programmable switches, for both security and performance. Our novel split-proxy defense leverages emerging programmable switches to block 100% of SYN floods in the switch data plane and also uses state-of-the-art kernel technologies such as eBPF to enable scalability for serving benign traffic. SMARTCOOKIE defends against adaptive adversaries at two orders of magnitude greater attack traffic than traditional CPU-based software defenses, blocking attacks of 136.9 Mpps without packet loss. We also achieve 2x-6.5x lower end-to-end latency for benign traffic compared to existing switch-based hardware defenses.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper7
- A Principled Approach for Detecting APTs in Massive Networks via Multi-Stage Causal AnalyticsJiaping Gui, Mingjie Nie, Jinyao Guo, Futai Zou 等INFOCOM 2025 · 被引用 6 次
- NetCap: Data-Plane Capability-Based Defense Against Token Theft in Network AccessOsama Bajaber, Bo Ji, Peng GaoNDSS 2026 · 被引用 2 次
- TurboRetry: Mitigating Large-Scale QUIC Handshake Floods with Off-the-Shelf DPU OffloadingJiahao Wu, Heng Pan, Kai Lv, Zhenyu Li 等CCS 2026
- When Address Learning Goes Wrong: Inducing Forwarding Loops and DoS Amplification in SDNDezhang Kong, Yilun Zhang, Zekun Xie, Ningpeng Zheng 等USENIX Security 2026
- On the Security Risks of Memory Adaptation and Augmentation in Data-plane DoS MitigationHocheol Nam, Daehyun Lim, Huancheng Zhou, Guofei Gu 等NDSS 2026
它引用的顶会 Paper7
- Understanding the Mirai BotnetManos Antonakakis, Tim April, Michael D. Bailey, Matt Bernhard 等USENIX Security 2017 · 被引用 2,003 次
- Jaqen: A High-Performance Switch-Native Approach for Detecting and Mitigating Volumetric DDoS Attacks with Programmable SwitchesZaoxing Liu, Hun Namkung, Georgios Nikolaidis, Jeongkeun Lee 等USENIX Security 2021 · 被引用 221 次
- Aggregate-based congestion control for pulse-wave DDoS defenseAlbert Gran Alcoz, Martin Strohmeier, Vincent Lenders, Laurent VanbeverSIGCOMM 2022 · 被引用 63 次
- RedPlane: enabling fault-tolerant stateful in-switch applicationsDaehyeok Kim, Jacob Nelson, Dan R. K. Ports, Vyas Sekar 等SIGCOMM 2021 · 被引用 33 次
- NeoBFT: Accelerating Byzantine Fault Tolerance Using Authenticated In-Network OrderingGuangda Sun, Mingliang Jiang, Xin Zhe Khooi, Yunfan Li 等SIGCOMM 2023 · 被引用 13 次
相关 Paper
- SYN Proof-of- Work: Improving Volumetric DoS Resilience in TCPSamuel DeLaughter, Karen R. SollinsS&P 2025
- Mew: Enabling Large-Scale and Dynamic Link-Flooding Defenses on Programmable SwitchesHuancheng Zhou, Sungmin Hong, Yangyang Liu, Xiapu Luo 等S&P 2023
- SPIFFY: Inducing Cost-Detectability Tradeoffs for Persistent Link-Flooding AttacksMin Suk Kang, Virgil D. Gligor, Vyas SekarNDSS 2016 · 被引用 123 次
- EqualNet: A Secure and Practical Defense for Long-term Network Topology ObfuscationJinwoo Kim, Eduard Marin, Mauro Conti, Seungwon ShinNDSS 2022
- Ripple: A Programmable, Decentralized Link-Flooding Defense Against Adaptive AdversariesJiarong Xing, Wenqing Wu, Ang ChenUSENIX Security 2021 · 被引用 100 次
