当前位置: X-MOL 学术Comput. Netw. › 论文详情
Our official English website, www.x-mol.net, welcomes your feedback! (Note: you will need to create a separate account there.)
The impact and mitigation of ICMP based economic denial of sustainability attack in cloud computing environment using software defined network
Computer Networks ( IF 5.6 ) Pub Date : 2021-01-07 , DOI: 10.1016/j.comnet.2021.107825
Sayed Qaiser Ali Shah , Farrukh Zeeshan Khan , Muneer Ahmad

High availability in network services is a crucial requirement for quality of experience. Denial of Service (DoS) and Distribute Denial of Service (DDoS) attacks are under contemplation by many researchers across the globe because these attacks directly target services availability. For this reason, cloud providers use the auto-scaling feature in Cloud Computing Environments (CCE), in which cloud resources scale dynamically on demand. DoS/DDoS attacks on CCE, using auto-scaling, do not deny services but cause high resource usage and substantial financial damages that become an Economic Denial of Sustainability (EDOS) attack. One of the DoS/DDoS attacks, resulting EDOS attack is the Internet Control Messaging Protocol (ICMP) flooding attack. In this paper, a novel technique, ICMP detection and mitigation model (EDOS-IDM) is proposed that can detect and mitigate Volumetric and Normal Behavioral ICMP traffic attacks. The results from the proposed technique are compared with the Normal Behavioral ICMP traffic attack because it causes least resource usage among all the mitigation techniques. According to our study, there is no such technique that can handle normal behavioral ICMP traffic attack. The technique is practically tested and evaluated on OpenStack production Cloud Environment test bed. According to the results, the technique is proved to save extra resource consumption and customer's bills in a cloud computing environment.



中文翻译:

使用软件定义网络在云计算环境中基于ICMP的经济否定可持续性攻击的影响和缓解

网络服务的高可用性是体验质量的关键要求。全球许多研究人员正在考虑拒绝服务(DoS)和分布式拒绝服务(DDoS)攻击,因为这些攻击直接针对服务的可用性。因此,云提供商使用云计算环境(CCE)中的自动扩展功能,其中云资源可按需动态扩展。使用自动扩展功能,对CCE的DoS / DDoS攻击不会拒绝服务,但会导致高资源使用率和大量财务损失,从而成为经济上的可持续发展(EDOS)攻击。导致EDOS攻击的一种DoS / DDoS攻击是Internet控制消息协议(ICMP)泛洪攻击。在本文中,一种新颖的技术 提出了ICMP检测和缓解模型(EDOS-IDM),该模型可以检测和缓解体积和正常行为ICMP流量攻击。将所提出的技术的结果与正常行为ICMP流量攻击进行比较,因为它在所有缓解技术中造成的资源使用最少。根据我们的研究,没有这样的技术可以处理正常的行为ICMP流量攻击。该技术已在OpenStack生产云环境测试平台上进行了实际测试和评估。根据结果​​,该技术被证明可以在云计算环境中节省额外的资源消耗和客户的账单。将所提出的技术的结果与正常行为ICMP流量攻击进行比较,因为它在所有缓解技术中造成的资源使用最少。根据我们的研究,没有这样的技术可以处理正常的行为ICMP流量攻击。该技术已在OpenStack生产云环境测试平台上进行了实际测试和评估。根据结果​​,该技术被证明可以在云计算环境中节省额外的资源消耗和客户的账单。将所提出的技术的结果与正常行为ICMP流量攻击进行比较,因为它在所有缓解技术中造成的资源使用最少。根据我们的研究,没有这样的技术可以处理正常的行为ICMP流量攻击。该技术已在OpenStack生产云环境测试平台上进行了实际测试和评估。根据结果​​,该技术被证明可以在云计算环境中节省额外的资源消耗和客户的账单。

更新日期:2021-01-16
down
wechat
bug