Please use this identifier to cite or link to this item: http://hdl.handle.net/10397/99840
PIRA download icon_1.1View/Download Full Text
DC FieldValueLanguage
dc.contributorDepartment of Computingen_US
dc.creatorZhou, Hen_US
dc.creatorHong, Sen_US
dc.creatorLiu, Yen_US
dc.creatorLuo, Xen_US
dc.creatorLi, Wen_US
dc.creatorGu, Gen_US
dc.date.accessioned2023-07-24T01:02:54Z-
dc.date.available2023-07-24T01:02:54Z-
dc.identifier.isbn978-1-6654-9336-9en_US
dc.identifier.urihttp://hdl.handle.net/10397/99840-
dc.description2023 IEEE Symposium on Security and Privacy (SP), May 22-26 2023, San Francisco, CA, USen_US
dc.language.isoenen_US
dc.rights© 2023, Huancheng Zhou. Under license to IEEE.en_US
dc.rightsPersonal use of this material is permitted. Permission from IEEE must be obtained for all other uses, in any current or future media, including reprinting/republishing this material for advertising or promotional purposes, creating new collective works, for resale or redistribution to servers or lists, or reuse of any copyrighted component of this work in other works.en_US
dc.rightsThe following publication H. Zhou, et al., "Mew: Enabling Large-Scale and Dynamic Link-Flooding Defenses on Programmable Switches," in 2023 IEEE Symposium on Security and Privacy (SP), San Francisco, CA, USA, 2023 pp. 3178-3192. doi: 10.1109/SP46215.2023.10179404 is available at https://www.computer.org/csdl/proceedings-article/sp/2023/933600b625/1Js0EbpFziM.en_US
dc.titleMew : enabling large-scale and dynamic link-flooding defenses on programmable switchesen_US
dc.typeConference Paperen_US
dc.identifier.spage3178en_US
dc.identifier.epage3192en_US
dc.identifier.doi10.1109/SP46215.2023.10179404en_US
dcterms.abstractLink-flooding attacks (LFAs) can cut off the Internet connection to selected server targets and are hard to mitigate because adversaries use normal-looking and low-rate flows and can dynamically adjust the attack strategy. Traditional centralized defense systems cannot locally and efficiently suppress malicious traffic. Though emerging programmable switches offer an opportunity to bring defense systems closer to targeted links, their limited resource and lack of support for runtime reconfiguration limit their usage for link-flooding defenses. We present Mew, a resource-efficient and runtime adaptable link-flooding defense system. Mew can counter various LFAs even when a massive number of flows are concentrated on a link, or when the attack strategy changes quickly. We design a distributed storage mechanism and a lossless state migration mechanism to reduce the storage bottleneck of programmable networks. We develop cooperative defense APIs to support multi-grained co-detection and co-mitigation without excessive overhead. Mew's dynamic defense mechanism can constantly analyze network conditions and activate corresponding defenses without rebooting devices or interrupting other running functions. We develop a prototype of Mew by using real-world programmable switches, which are located in five cities. Our experiments show that the real-world prototype can defend against large-scale and dynamic LFAs effectively.en_US
dcterms.accessRightsopen accessen_US
dcterms.bibliographicCitation2023 IEEE Symposium on Security and Privacy (SP), San Francisco, CA, US, 2023 p. 3178-3192en_US
dcterms.issued2023-
dc.relation.conferenceIEEE Symposium on Security and Privacy [SP]en_US
dc.description.validate202307 bcwwen_US
dc.description.oaAccepted Manuscripten_US
dc.identifier.FolderNumbera2291-
dc.identifier.SubFormID47361-
dc.description.fundingSourceSelf-fundeden_US
dc.description.pubStatusPublisheden_US
dc.description.oaCategoryGreen (AAM)en_US
Appears in Collections:Conference Paper
Files in This Item:
File Description SizeFormat 
Zhou_Mew_Enabling_Large-scale.pdfPre-Published version2.79 MBAdobe PDFView/Open
Open Access Information
Status open access
File Version Final Accepted Manuscript
Access
View full-text via PolyU eLinks SFX Query
Show simple item record

Page views

124
Citations as of Apr 14, 2025

Downloads

51
Citations as of Apr 14, 2025

Google ScholarTM

Check

Altmetric


Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.