首页> 外文期刊>Concurrency, practice and experience >A trust-based hypervisor framework for preventing DDoS attacks in cloud
【24h】

A trust-based hypervisor framework for preventing DDoS attacks in cloud

机译:基于信任的虚拟机管理程序框架,用于防止云中的DDOS攻击

获取原文
获取原文并翻译 | 示例

摘要

Distributed Denial of Service (DDoS) attack is one of the major attacks that incur large financial loss in the cloud system. This motivated the research community to develop various detection techniques for controlling the effects of the DDoS attack. However, the existing techniques are not mature to satisfy the requirements of a cloud-based attack detection system, as they manage the devious strategies that exploit the elastic and multi-tenant properties of the cloud and ignore the resource constraints of the cloud system. This paper proposes a new solution that allows the hypervisor to establish trust-based relationships towards the guest Virtual Machines (VMs). The Bayesian inference is applied to aggregate the objective and subjective trust sources. A trust-based maximin game between DDoS attackers is designed. A hypervisor tries to maximize the attack minimization under a limited amount of resources. The game solution guides the hypervisor to determine the distribution of optimal detection load among VMs to improve the real-time detection rate of DDoS attack. The Least Squares Support Vector Machine (LS-SVM) classification is applied to classify the normal VMs and malicious VMs. The file is allocated to the VM based on the storage capacity of the VM. The experimental result shows that the proposed approach achieves high DDoS attack detection rate with minimum false positive and negative rate, when compared to the existing attack detection models.
机译:分布式拒绝服务(DDOS)攻击是云系统中产生大型财务损失的主要攻击之一。这激发了该研究界,开发了用于控制DDOS攻击影响的各种检测技术。然而,现有技术不成熟,以满足基于云的攻击检测系统的要求,因为它们管理利用云的弹性和多租户属性的狡猾策略并忽略云系统的资源限制。本文提出了一种新的解决方案,允许管理程序为客户虚拟机(VM)建立基于信任的关系。贝叶斯推论适用于聚合目标和主观信任来源。设计了一个基于信任的Maximin游戏,设计了DDOS攻击者。管理程序尝试在有限的资源下最大限度地提高攻击最小化。游戏解决方案指导虚拟机管理程序以确定VM之间的最佳检测负载的分布,以提高DDOS攻击的实时检测速率。应用最小二乘支持向量机(LS-SVM)分类以对普通VM和恶意VM进行分类。根据VM的存储容量,该文件分配给VM。实验结果表明,与现有的攻击检测模型相比,该方法具有最小误态和负速率的高DDOS攻击检测率。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号