首页> 外文期刊>Future generation computer systems >HostWatcher: Protecting hosts in cloud data centers through software-defined networking
【24h】

HostWatcher: Protecting hosts in cloud data centers through software-defined networking

机译:HostWatcher:通过软件定义的网络保护云数据中心中的主机

获取原文
获取原文并翻译 | 示例
           

摘要

Cloud has become a dominant computing platform, and cloud data centers have been widely deployed all over the world. Naturally, cloud data centers become the targets of cyber attacks due to the feature of publicity. In addition, the price of renting resources from cloud constantly gets cheaper and cheaper. Therefore, attackers can rent hosts from cloud data centers to initiate attacks with rather low cost. As a result, hosts in a cloud center could be either victims or attackers. However, most existing researches only treat the hosts as the targets or the sources of attacks, either protecting the hosts from being attacked or identifying the malicious hosts, which is insufficient to protect the cloud data centers comprehensively. In this paper, we hire the novel techniques of SDN to protect the cloud data centers in both directions. Aiming at mitigating DDoS attacks, we propose HostWatcher, a system that watches and protects every host in cloud data center. HostWatcher leverages the advantages of SDN techniques and distributed processing. Caching and round-robin-resending scheme is introduced to the proposed system. Our goal is to protect the hosts comprehensively with QoS guarantee. The extensive experiments show that HostWatcher can effectively mitigate the DDoS attacks that target the hosts. Meanwhile, HostWatcher can also significantly limit the packet rate of hosts that are controlled by attackers. Also, the comprehensive evaluations show that the overheads of our system are trivial, and that our system is practical to implement and deploy in the cloud data centers.
机译:云已经成为主导的计算平台,并且云数据中心已在全球范围内广泛部署。自然,由于宣传的特性,云数据中心成为网络攻击的目标。此外,从云租用资源的价格越来越便宜。因此,攻击者可以从云数据中心租用主机,从而以较低的成本发起攻击。结果,云中心中的主机可能是受害者,也可能是攻击者。但是,大多数现有研究仅将主机视为攻击的目标或攻击源,既不能保护主机免受攻击,也不能识别恶意主机,这不足以全面保护云数据中心。在本文中,我们采用了SDN的新颖技术来双向保护云数据中心。为了减轻DDoS攻击,我们建议使用HostWatcher,该系统可以监视和保护云数据中心中的每个主机。 HostWatcher利用SDN技术和分布式处理的优势。高速缓存和循环发送方案被引入到该系统中。我们的目标是通过QoS保证全面保护主机。广泛的实验表明,HostWatcher可以有效缓解针对主机的DDoS攻击。同时,HostWatcher还可以大大限制攻击者控制的主机的数据包速率。此外,综合评估表明,我们的系统的开销很小,而且我们的系统对于在云数据中心中实施和部署非常实用。

著录项

  • 来源
    《Future generation computer systems》 |2020年第4期|964-972|共9页
  • 作者

  • 作者单位

    Cluster and Grid Computing Lab Services Computing Technology and System Lab Big Data Technology and System Lab Huazhong University of Science and Technology Wuhan 430074 China;

    School of IT Deakin University Victoria 3125 Australia;

    Cyber-Physical-Social Systems Lab School of Computer Science and Technology Huazhong University of Science and Technology Wuhan 430074 China Department of Computer Science St. Francis Xavier University Antigonish NS Canada;

  • 收录信息 美国《科学引文索引》(SCI);美国《工程索引》(EI);
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Software-defined network; Cloud data center network; DDoS attack; Mitigation;

    机译:软件定义的网络;云数据中心网络;DDoS攻击;减轻;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号