Leveraging In-band Network Telemetry for Automated DDoS Detection in Production Programmable Networks: The AmLight Use Case | IEEE Conference Publication | IEEE Xplore

Leveraging In-band Network Telemetry for Automated DDoS Detection in Production Programmable Networks: The AmLight Use Case


Abstract:

Programmable data planes have provided great flexibility in defining the behaviors of packet forwarding switches, routers, and network interface cards (NICs). The In-band...Show More

Abstract:

Programmable data planes have provided great flexibility in defining the behaviors of packet forwarding switches, routers, and network interface cards (NICs). The In-band Network Telemetry (INT) technology further increased network operators’ potential to manage packet flows by enabling real-time and customizable monitoring of packets without creating much overhead on the network. These recent advancements in networking technology have generated significant research interest and activity, including studies on INT-based DDoS detection and mitigation mechanisms. However, in practice, INT technology has not been fully realized yet, especially in detecting network anomalies in real-time. There is also a gap in the literature that provides a comparative evaluation of INT-based solutions against existing alternatives. In this paper, we aim to implement a holistic real-time INT-based DDoS detection mechanism. The proposed mechanism will retrieve INT data from the network, analyze it using machine learning (ML) models in real-time, and send the information to the control plane. We will also compare the performance of using INT to detect DDoS attacks against sFlow-based detection.
Date of Conference: 17-22 November 2024
Date Added to IEEE Xplore: 08 January 2025
ISBN Information:
Conference Location: Atlanta, GA, USA

Funding Agency:


Contact IEEE to Subscribe

References

References is not available for this document.