估计不够:基于逐包均匀性检验的地毯式轰炸检测
Estimation is Not Enough: Carpet-Bombing Detection via Per-Packet Uniformity Testing
- University of Jinan(济南大学)
- Quan Cheng Laboratory(泉城实验室)
机构由 AI 辅助整理,请以论文原文为准。
AI总结:
针对地毯式轰炸攻击检测延迟过高的问题,提出首个基于sketch的检测模型SweepSketch,锚定目的侧,压缩T-HLL、CUSUM和双EWMA到44字节桶,在Tofino2上部署,F1达0.991,中位延迟186-627毫秒。
AI中文摘要:
地毯式轰炸攻击将流量均匀地分散到一个或多个目的IP前缀,使前缀中的每台主机都保持在告警阈值以下,同时耗尽前缀级防御。现有的地毯式轰炸检测器运行延迟为秒级到分钟级,无法在攻击窗口内及时响应。Sketch支持在固定宽度内存中进行逐包处理,是降低延迟的自然选择,但目前尚不存在基于sketch的地毯式轰炸检测器。由于源地址可以被伪造,且攻击可通过反射发起,源侧证据在结构上不可用,检测必须锚定在目的侧。我们提出SweepSketch,这是首个基于sketch的地毯式轰炸检测模型:它锚定在目的侧,不保留源状态,并将带标签的自清洁T-HLL原语、逐包CUSUM决策和双EWMA变化门压缩为44字节的固定宽度桶,可部署在Tofino2可编程交换机上。其设计由六个定理支撑,包括可验证的检测下界。在相同内存预算下,SweepSketch在sketch、熵和序贯检验类别的全部10个基线中F1分数领先(0.991)。其中位告警延迟为186–627毫秒,并对源地址伪造具有结构性免疫。在从参数设计中留出的30个真实/合成多前缀样本上,它检测出全部140个受害前缀。
英文摘要:
Carpet-bombing attacks spread traffic uniformly across one or more destination IP prefixes, keeping every host in the prefix below alarm thresholds while exhausting prefix-level defenses. Existing carpet-bombing detectors run at seconds-to-minutes latency, too slow to respond within the attack window. Sketches support per-packet processing in fixed-width memory, a natural fit for cutting latency, yet no sketch-based detector exists for carpet bombing. Because source addresses can be spoofed, and attacks can be launched through reflection, source-side evidence is structurally unavailable and detection must anchor at the destination side. We present SweepSketch, the first sketch-based detection model for carpet bombing: it anchors at the destination, keeps no source state, and compresses a tagged self-cleaning T-HLL primitive, per-packet CUSUM decisions, and dual-EWMA change gates into 44-byte fixed-width buckets deployable on the Tofino2 programmable switch. Its design is supported by six theorems, including verifiable detection lower bounds. Under the same memory budget, SweepSketch leads all 10 baselines across the sketch, entropy, and sequential-testing classes in F1 (0.991). Its median alarm latency is 186--627 ms, and it has structural immunity to source spoofing. On 30 real/synthetic multi-prefix samples held out from parameter design, it detects all 140 victim prefixes.