Show simple item record

dc.contributor.authorFebro, Aldo
dc.contributor.authorXiao, Hannan
dc.contributor.authorSpring, William Joseph
dc.contributor.authorChristianson, Bruce
dc.date.accessioned2022-08-09T11:30:02Z
dc.date.available2022-08-09T11:30:02Z
dc.date.issued2022-10-24
dc.identifier.citationFebro , A , Xiao , H , Spring , W J & Christianson , B 2022 , ' Synchronizing DDoS Defense at Network Edge with P4, SDN, and Blockchain ' , Computer Networks , vol. 216 , 109267 . https://doi.org/10.1016/j.comnet.2022.109267
dc.identifier.issn1389-1286
dc.identifier.otherORCID: /0000-0002-2251-2838/work/117176385
dc.identifier.urihttp://hdl.handle.net/2299/25707
dc.description© 2022 Elsevier B.V. All rights reserved. This is the accepted manuscript version of an article which has been published in final form at https://doi.org/10.1016/j.comnet.2022.109267
dc.description.abstractBotnet-originated DDoS attacks continue to plague the internet and disrupt services for legitimate users. While various proposals have been presented in the last two decades, the botnet still has advantages over the defenders, because botnets have orchestrated processes to launch disruptive attacks. On the other hand, the defenders use manual methods, siloed tools, and lack orchestration among different organizations. These unorchestrated efforts slow down the attack response and extend the lifespan of botnet attacks. This article presents shieldSDN and shieldCHAIN, an inter-organization collaborative defense framework using P4, SDN, and Blockchain, which extends our earlier research on microVNF, a solution of Edge security for SIP- enabled IoT devices with P4. Besides mitigating DDoS attacks, microVNF also produces attack fingerprints called Indicator of Compromise (IOC) records. ShieldSDN and shieldCHAIN dis- tribute these IOCs to other organizations so that they can create their own packet filters. Effectively, shieldSDN and shieldCHAIN synchronize packet filters for different organizations to mitigate against the same botnet strain. Four experiments were performed successfully to validate the functionalities of shieldSDN and shieldCHAIN. The scope for the first experiment was intra- company, while the second, third, and fourth experiments were inter-company. In the first experiment, shieldSDN extracted IOCs from the source switch and installed these as packet filters on other switches within the same organization (in the U.S.). In the second experiment, the shieldCHAIN in the publishing organization (in the U.S.) shared IOCs by posting them to the Blockchain. In the third experiment, the shieldCHAIN in the subscriber organizations (in Singapore & the U.K.) retrieved these IOCs from Blockchain. Finally, in the last experiment, the shieldCHAIN in the subscriber organizations installed the retrieved IOCs as packet filters; that are identical to those in the originating organization. To the best of our knowledge, this is the first framework that uses the P4 switch, SDN controller, and Blockchain together for this use case. As SDN and Blockchain gain acceptance, this framework empowers community members to collaborate and defend against botnet DDoS attacks.en
dc.format.extent24
dc.format.extent2447147
dc.language.isoeng
dc.relation.ispartofComputer Networks
dc.subjectBlockchain
dc.subjectDAO
dc.subjectDDoS
dc.subjectNFT
dc.subjectP4
dc.subjectSDN
dc.subjectComputer Networks and Communications
dc.titleSynchronizing DDoS Defense at Network Edge with P4, SDN, and Blockchainen
dc.contributor.institutionDepartment of Computer Science
dc.contributor.institutionSchool of Physics, Engineering & Computer Science
dc.contributor.institutionCentre for Computer Science and Informatics Research
dc.contributor.institutionScience & Technology Research Institute
dc.contributor.institutionSchool of Computer Science
dc.description.statusPeer reviewed
dc.date.embargoedUntil2023-08-06
dc.identifier.urlhttp://www.scopus.com/inward/record.url?scp=85136873843&partnerID=8YFLogxK
rioxxterms.versionofrecord10.1016/j.comnet.2022.109267
rioxxterms.typeJournal Article/Review
herts.preservation.rarelyaccessedtrue


Files in this item

Thumbnail

This item appears in the following Collection(s)

Show simple item record