Detecting Denial of Service Attacks in the Cloud
Autor: | Alok Sharma, Raneel Kumar, Sunil Pranit Lal |
---|---|
Rok vydání: | 2016 |
Předmět: |
business.industry
Computer science ComputerSystemsOrganization_COMPUTER-COMMUNICATIONNETWORKS 020206 networking & telecommunications Denial-of-service attack Cloud computing 02 engineering and technology Intrusion detection system UDP flood attack computer.software_genre Internet Control Message Protocol Virtual machine Packet analyzer 0202 electrical engineering electronic engineering information engineering 020201 artificial intelligence & image processing SYN flood business computer Computer network |
Zdroj: | DASC/PiCom/DataCom/CyberSciTech |
Popis: | In this paper, an approach to protecting virtual machines (VMs) against denial of service (DoS) attacks in a cloud environment is proposed. An open source cloud computing platform (Eucalyptus) has been deployed, and experimentation was carried out on this setup. We investigate attacks emanating from one or more virtual machines (VMs) to another VM in a multi-tenancy cloud environment. Various types of DoS attacks are mounted on a webserver VM. To detect such attacks from a cloud provider's perspective, an intrusion detection system (IDS) is needed. In this research we propose and implement an IDS which incorporates a packet sniffer, feature extractor and a classifier as part of its design. We have experimented with the one-class support vector machines (SVM) algorithm for classification of the attacks. The dataset containing time-based traffic flow features is passed through the classifier to detect the attack traffic from legitimate traffic. The proposed IDS design shows promising results in being able to detect the ICMP Flood, Ping-of-Death, UDP Flood, TCP SYN Flood, TCP LAND and DNS Flood attacks with high classification accuracies. |
Databáze: | OpenAIRE |
Externí odkaz: |