• KSII Transactions on Internet and Information Systems
    Monthly Online Journal (eISSN: 1976-7277)

A Blockchain-enabled Multi-domain DDoS Collaborative Defense Mechanism


Abstract

Most of the existing Distributed Denial-of-Service mitigation schemes in Software-Defined Networking are only implemented in the network domain managed by a single controller. In fact, the zombies for attackers to launch large-scale DDoS attacks are actually not in the same network domain. Therefore, abnormal traffic of DDoS attack will affect multiple paths and network domains. A single defense method is difficult to deal with large-scale DDoS attacks. The cooperative defense of multiple domains becomes an important means to effectively solve cross-domain DDoS attacks. We propose an efficient multi-domain DDoS cooperative defense mechanism by integrating blockchain and SDN architecture. It includes attack traceability, inter-domain information sharing and attack mitigation. In order to reduce the length of the marking path and shorten the traceability time, we propose an AS-level packet traceability method called ASPM.We propose an information sharing method across multiple domains based on blockchain and smart contract. It effectively solves the impact of DDoS illegal traffic on multiple domains. According to the traceability results, we designed a DDoS attack mitigation method by replacing the ACL list with the IP address black/gray list. The experimental results show that our ASPM traceability method requires less data packets, high traceability precision and low overhead. And blockchain-based inter-domain sharing scheme has low cost, high scalability and high security. Attack mitigation measures can prevent illegal data flow in a timely and efficient manner.


Statistics

Show / Hide Statistics

Statistics (Cumulative Counts from December 1st, 2015)
Multiple requests among the same browser session are counted as one view.
If you mouse over a chart, the values of data points will be shown.


Cite this article

[IEEE Style]
H. Feng, Y. Liu, X. Yan, N. Zhou, Z. Jiang, "A Blockchain-enabled Multi-domain DDoS Collaborative Defense Mechanism," KSII Transactions on Internet and Information Systems, vol. 17, no. 3, pp. 916-937, 2023. DOI: 10.3837/tiis.2023.03.013.

[ACM Style]
Huifen Feng, Ying Liu, Xincheng Yan, Na Zhou, and Zhihong Jiang. 2023. A Blockchain-enabled Multi-domain DDoS Collaborative Defense Mechanism. KSII Transactions on Internet and Information Systems, 17, 3, (2023), 916-937. DOI: 10.3837/tiis.2023.03.013.

[BibTeX Style]
@article{tiis:38512, title="A Blockchain-enabled Multi-domain DDoS Collaborative Defense Mechanism", author="Huifen Feng and Ying Liu and Xincheng Yan and Na Zhou and Zhihong Jiang and ", journal="KSII Transactions on Internet and Information Systems", DOI={10.3837/tiis.2023.03.013}, volume={17}, number={3}, year="2023", month={March}, pages={916-937}}