Tracking Normalized Network Traffic Entropy to Detect DDoS Attacks in P4
Abstract
Domain fit: Niche / domain-specific · No strong AI-core implementation/artifact signals were detected from current providers.
Distributed Denial-of-Service (DDoS) attacks represent a persistent threat to modern telecommunications networks: detecting and counteracting them is still a crucial unresolved challenge for network operators. DDoS attack detection is usually carried out in one or more central nodes that collect significant amounts of monitoring data from networking devices, potentially creating issues related to network overload or delay in detection. The dawn of programmable data planes in Software-Defined Networks can help mitigate this issue, opening the door to the detection of DDoS attacks directly in the data plane of the switches. However, the most widely-adopted data plane programming language, namely P4, lacks supporting many arithmetic operations, therefore, some of the advanced network monitoring functionalities needed for DDoS detection cannot be straightforwardly implemented in P4. This work overcomes such a limitation and presents two novel strategies for flow cardinality and for normalized network traffic entropy estimation that only use P4-supported operations and guarantee a low relative error. Additionally, based on these contributions, we propose a DDoS detection strategy relying on variations of the normalized network traffic entropy. Results show that it has comparable or higher detection accuracy than state-of-the-art solutions, yet being simpler and entirely executed in the data plane.
Results and benchmarks
Distributed Denial-of-Service (DDoS) attacks represent a persistent threat to modern telecommunications networks: detecting and counteracting them is still a crucial unresolved challenge for network operators.
Benchmark evidence is limited
Evidence graph: 2 refs, 1 links.
Utility signals: depth 65/100, grounding 58/100, status medium.
Implementation
No direct implementation yet
Maintained implementation evidence is not confirmed for this paper yet.
Use the implementation status and reproduction sections for the current action plan.
No verified maintained repo yet
There is no verified maintained implementation yet. Use this baseline plan to decide whether to prototype now or defer.
- No direct maintained implementation was found. Use the paper PDF and citation graph to design a baseline reproduction.
- Start from related paper: Detection techniques of DDoS attacks: A survey.
- Track assumptions and missing details in an experiment log before coding.
Time to first repro: a few days
Recommendation evidence is currently too limited for a maintained-repo choice. Use Implementation Status and Reproduction Path for a practical baseline plan.
- Estimate is based on paper-only reproduction flow
Reproduction readiness
No repo
No verified implementation available
- No maintained repository has been identified for this paper. Check adjacent implementations or HF artifacts below.
Hardware requirements
- Expect multi-day setup/compute for meaningful reproduction based on current guidance.
Validation caveat
Hugging Face artifacts
No trustworthy direct or curated related Hugging Face artifacts were found yet. Use targeted searches to quickly locate candidate models, datasets, and demos.
Tip: start with models, then check datasets and spaces if you need evaluation data or demos.
Research context
44
Citations
33
References
Tasks
Denial-of-service attack, Computer science, Forwarding plane, Trinoo, Application layer DDoS attack, Network monitoring, Software-defined networking, Entropy (arrow of time)
Methods
None detected
Domains
Network security, Computer security
Related papers
- Detection techniques of DDoS attacks: A surveySearch on Paper2Code
2017 · Semantic similarity
- Convolutional Neural Network-Based Automatic Diagnostic System for AL-DDoS Attacks DetectionSearch on Paper2Code
2022 · Semantic similarity
- Packet Simulation of Distributed Denial of Service (DDoS) Attack and RecoverySearch on Paper2Code
2013 · Semantic similarity
- DDoS Mitigation: A review of Content Delivery Network and its DDoS Defence techniquesSearch on Paper2Code
2020 · Semantic similarity
- Keynote III: Detection and traceback of DDoS attacksSearch on Paper2Code
2008 · Semantic similarity
- Defence of DDoSSearch on Paper2Code
2009 · Semantic similarity
Jump to Paper2Code search queries derived from this paper's research context.