A cloud tracing and filtering framework for defensing against denial of service attacks

被引:0
作者
Lin F. [1 ]
Zeng W. [2 ]
Jiang Y. [3 ]
机构
[1] School of Software, Xiamen University
[2] Fujian Key Laboratory of the Brain-Like Intelligent Systems, Xiamen University
[3] Department of Computer Science, Xiamen University
关键词
Cloud computing; Denial of service attacks; Network security; SaaS;
D O I
10.4156/jdcta.vol4.issue9.26
中图分类号
学科分类号
摘要
Cloud computing is Internet-based computing, whereby shared resources, software, and nformation are provided to computers and other devices on demand, like the electricity grid. One of the most serious threats to cloud computing itself comes from Denial of Service attacks, especially HTTP or XML-Based Denial of Service attacks. These types of attacks are simple and easy to implement by the attacker, but to security experts they are twice as difficult to stop. In this paper, we introduced a security service called Cloud Tracing & Filtering (CTF), which is like a service broker within a SOA model, and a back propagation neutral network called Cloud Shield, which was trained to detect and filter DoS attack traffic. And we also presented a solution to detect and trace through CTF to find the source of those attacks. The experimental results show that CTF is able to detect and filter most of the attack messages and to identify the source of the attack within a short period of time.
引用
收藏
页码:212 / 224
页数:12
相关论文
共 37 条
  • [1] Amazon Elastic Compute Cloud (ec2), (2009)
  • [2] Balding G., What Everyone Ought to Know About Cloud Security, (2009)
  • [3] Belenky A., Ansari N., Tracing multiple attackers with deterministic packet marking (DPM), Computers and Signal Processing, 1, pp. 49-52, (2003)
  • [4] Danchev D., Iranian opposition launches organized cyber attack against pro-Ahmadinejad sites, ZDNet Blog
  • [5] Danchev D., Iranian Opposition DDoS-es Pro Ahmadinejad Sites. Dancho Danchev's Blog
  • [6] Dean D., An Algebraic Approach to IP Traceback, 5, 2, (2002)
  • [7] Dittrich D., The ''mstream'' Distributed Denial of Service Attack Tool, (2000)
  • [8] Dittrich D., The DoS Project's ''trinoo'' Distributed Denial of Service Attack Tool
  • [9] E-Crime Survey
  • [10] Cloud Hosting