Skip to main content
QUICK REVIEW

[论文解读] The role of Blockchain in DDoS attacks mitigation: techniques, open challenges and future directions

Rajasekhar Chaganti, Bharat Bhushan|arXiv (Cornell University)|Feb 8, 2022
Network Security and Intrusion Detection被引用 14
一句话总结

本文提出了一种基于区块链的框架,通过利用去中心化信任、智能合约以及在物联网、软件定义网络(SDN)和云环境中的威胁信息共享,以减轻分布式拒绝服务(DDoS)攻击。该研究按部署位置对现有解决方案进行分类——基于网络、靠近攻击者、靠近受害者以及混合式——表明区块链能够增强检测与协调能力,同时识别出可扩展性和互操作性是关键挑战。

ABSTRACT

With the proliferation of new technologies such as Internet of Things (IOT) and Software-Defined Networking(SDN) in the recent years, the distributed denial of service (DDoS)attack vector has broadened and opened new opportunities for more sophisticated DDoS attacks on the targeted victims. The new attack vector includes unsecured and vulnerable IoT devices connected to the internet, denial of service vulnerabilities like southbound channel saturation in the SDN architecture. Given the high-volume and pervasive nature of these attacks, it is beneficial for stakeholders to collaborate in detecting and mitigating the denial of service attacks in a timely manner. The blockchain technology is considered to improve the security aspects owing to the decentralized design, secured distributed storage and privacy. A thorough exploration and classification of blockchain techniques used for DDoS attack mitigation is not explored in the prior art. This paper reviews and categorizes the existed state-of-the-art DDoS mitigation solutions based on blockchain technology. The DDoS mitigation techniques are classified based on the solution deployment location i.e. network based, near attacker location, near victim location and hybrid solutions in the network architecture with emphasis on the IoT and SDN architectures. Additionally, based on our study, the research challenges and future directions to implement the blockchain based DDoS mitigation solutions are discussed. We believe that this paper could serve as a starting point and reference resource for future researchers working on denial of service attacks detection and mitigation using blockchain technology.

研究动机与目标

  • 应对由物联网和软件定义网络(SDN)技术加剧的DDoS攻击日益增长的威胁。
  • 识别现有DDoS缓解技术的局限性,特别是在检测新型或演变型攻击模式方面的不足。
  • 根据网络架构中的部署位置,系统性地对基于区块链的DDoS缓解解决方案进行分类。
  • 突出区块链集成DDoS防御中面临的开放挑战,如可扩展性、延迟和互操作性。
  • 概述利用以太坊2.0、并行区块链和Xrouter等新兴区块链技术的未来研究方向。

提出的方法

  • 将现有的基于区块链的DDoS缓解解决方案划分为四种部署类别:基于网络、靠近攻击者、靠近受害者以及混合架构。
  • 在许可或联盟链上使用智能合约,以在自治系统之间存储和分发恶意IP地址。
  • 在网关设备中集成可编程数据平面(P4),以实现对流量的实时检查和自动缓解操作。
  • 利用去中心化存储系统(如IPFS和Swarm)将威胁情报数据离链存储,以减少区块链上的交易负载。
  • 提出采用以太坊2.0的权益证明共识机制,以提升交易吞吐量并降低DDoS缓解事务处理的Gas成本。
  • 探索新兴技术,如并行区块链(例如Paralism)和跨链路由器(例如Xrouter),以实现可扩展的多链威胁数据共享。

实验结果

研究问题

  • RQ1区块链技术如何在物联网、SDN和云等不同网络层级中有效部署,以缓解DDoS攻击?
  • RQ2在攻击者附近、受害者附近或网络核心部署DDoS缓解解决方案,各自的相对优势和局限性是什么?
  • RQ3以太坊2.0、并行区块链和Xrouter等新兴区块链进展如何提升DDoS缓解系统的可扩展性和性能?
  • RQ4在将区块链与实时DDoS检测和响应机制集成时,面临的关键开放挑战是什么?
  • RQ5如何利用区块链实现各利益相关方之间安全、匿名且高效的威胁信息共享?

主要发现

  • 大多数现有的基于区块链的DDoS缓解解决方案集中于通过智能合约在基于网络或靠近攻击者的部署中存储和分发恶意IP地址。
  • 靠近受害者和混合部署模式仍研究不足,表明在本地化、响应式缓解策略方面存在研究空白。
  • 以太坊2.0向权益证明的转变预计将显著提升交易吞吐量并降低延迟,使其在实时DDoS缓解中更具可行性。
  • 如Paralism等并行区块链架构提供无限可扩展性,并支持多个子链,从而实现高效的应用间威胁数据共享。
  • 跨链通信工具如Xrouter可实现区块链之间的互操作性,这对于构建统一的去中心化威胁情报网络至关重要。
  • 去中心化存储系统(如IPFS和Swarm)通过将大型威胁指标离链存储,减少了链上数据膨胀,同时保持了数据的完整性和可用性。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。