首页> 外文会议>IEEE Conference on Local Computer Networks >Whack-a-Mole: Software-defined Networking driven Multi-level DDoS defense for Cloud environments
【24h】

Whack-a-Mole: Software-defined Networking driven Multi-level DDoS defense for Cloud environments

机译:Whack-a-Mole:适用于云环境的软件定义的网络驱动多级DDoS防御

获取原文

摘要

With wider adoption of Software-Defined Networking (SDN), network obfuscation and resource adaptation within a cloud environment have emerged as cost-effective solutions against cyber attacks. In spite of their implementation simplicity, shortcomings of such one-dimensional strategies are considerable against sophisticated attacks where the attacker/s have enhanced visibility to the cloud network. In this paper, we propose Whack-a-Mole, a SDN-driven cloud resource management scheme through network obfuscation that can help Cloud Service Providers (CSPs) to: a) proactively protect critical services from impending DDoS attacks and b) contribute very little service interruption footprint while doing so. Whack-a-Mole works at two levels: it employs a novel virtual machine (VM) spawning model that not only creates multiple VM-replicas of critical services to new cloud resource instances, but also assigns VM-replicas' IP addresses through address space randomization. Using numerical results, we show how such VM spawning can be optimized based on realistic cloud Service Level Agreements (SLA) without compromising its effectiveness. Finally, Whack-a-Mole is implemented through SDN/OpenFlow controllers over Open vSwitches on a GENI testbed where the efficacy and effectiveness of the scheme is evaluated. The results show Whack-a-Mole to be as effective as random obfuscation in evading attack events and more than 2x better on average in attack avoidance over other static resource adaptation based defense strategies.
机译:随着软件定义网络(SDN)的广泛采用,云环境中的网络混淆和资源自适应已成为抵御网络攻击的经济高效的解决方案。尽管实施简单,但是这种一维策略的缺点对于复杂的攻击而言是相当大的,在复杂的攻击中,攻击者对云网络的可见性得到了增强。在本文中,我们提出了Whack-a-Mole,这是一种通过网络模糊处理由SDN驱动的云资源管理方案,可以帮助云服务提供商(CSP):a)主动保护关键服务免受即将来临的DDoS攻击,并且b)贡献很少这样做时会中断服务。 Whack-a-Mole在两个级别上工作:它采用新颖的虚拟机(VM)生成模型,该模型不仅为新的云资源实例创建关键服务的多个VM副本,而且还通过地址空间分配VM副本的IP地址。随机化。使用数值结果,我们展示了如何基于现实的云服务级别协议(SLA)优化此类VM生成,而又不影响其有效性。最后,Whack-a-Mole通过SDN / OpenFlow控制器在GENI测试平台上的Open vSwitch上实现,在该平台上评估了该方案的有效性和有效性。结果表明,与其他基于静态资源自适应的防御策略相比,Whack-a-Mole在规避攻击事件方面的效果与随机混淆效果相同,并且在避免攻击方面的平均效果要高出两倍以上。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号