Can we beat DDoS attacks in clouds?
Version 2 2024-06-05, 05:25Version 2 2024-06-05, 05:25
Version 1 2014-01-01, 00:00Version 1 2014-01-01, 00:00
journal contribution
posted on 2024-06-05, 05:25 authored by S Yu, Y Tian, S Guo, DO WuCloud is becoming a dominant computing platform. Naturally, a question that arises is whether we can beat notorious DDoS attacks in a cloud environment. Researchers have demonstrated that the essential issue of DDoS attack and defense is resource competition between defenders and attackers. A cloud usually possesses profound resources and has full control and dynamic allocation capability of its resources. Therefore, cloud offers us the potential to overcome DDoS attacks. However, individual cloud hosted servers are still vulnerable to DDoS attacks if they still run in the traditional way. In this paper, we propose a dynamic resource allocation strategy to counter DDoS attacks against individual cloud customers. When a DDoS attack occurs, we employ the idle resources of the cloud to clone sufficient intrusion prevention servers for the victim in order to quickly filter out attack packets and guarantee the quality of the service for benign users simultaneously. We establish a mathematical model to approximate the needs of our resource investment based on queueing theory. Through careful system analysis and real-world data set experiments, we conclude that we can defeat DDoS attacks in a cloud environment. © 2013 IEEE.
History
Related Materials
- 1.
Location
Piscataway, N.J.Language
engPublication classification
C Journal article, C1 Refereed article in a scholarly journalCopyright notice
2014, IEEEJournal
IEEE transactions on parallel and distributed systemsVolume
25Pagination
2245-2254ISSN
1045-9219Issue
9Publisher
IEEEUsage metrics
Categories
Keywords
Cloud computingDDoS attacksmitigationresource investmentsystem modellingScience & TechnologyTechnologyComputer Science, Theory & MethodsEngineering, Electrical & ElectronicComputer ScienceEngineeringNETWORK080503 Networking and Communications890101 Fixed Line Data Networks and ServicesSchool of Information Technology
Licence
Exports
RefWorksRefWorks
BibTeXBibTeX
Ref. managerRef. manager
EndnoteEndnote
DataCiteDataCite
NLMNLM
DCDC

