...
首页> 外文期刊>Network and Service Management, IEEE Transactions on >Frequency-Minimal Utility-Maximal Moving Target Defense Against DDoS in SDN-Based Systems
【24h】

Frequency-Minimal Utility-Maximal Moving Target Defense Against DDoS in SDN-Based Systems

机译:基于SDN的系统中对DDOS的频率最小实用 - 最大移动目标防御

获取原文
获取原文并翻译 | 示例
           

摘要

With the increase of DDoS attacks, resource adaptation schemes need to be effective to protect critical cloud-hosted applications. Specifically, they need to be adaptable to attack behavior, and be dynamic in terms of resource utilization. In this paper, we propose an intelligent strategy for proactive and reactive application migration by leveraging the concept of 'moving target defense' (MTD). The novelty of our approach lies in: (a) stochastic proactive migration frequency minimization across heterogeneous cloud resources to optimize migration management overheads, (b) market-driven migration location selection during proactive migration to optimize resource utilization, cloud service providers (CSPs) cost and user quality of experience, and (c) fast converging cost-minimizing reactive migration coupled with a 'false reality' pretense to reduce the future attack success probability. We evaluate the effectiveness of our proposed MTD-based defense strategy using a Software-defined Networking (SDN) enabled GENI Cloud testbed for a "Just-in-time news articles and video feeds" application. Our frequency minimization results show more than 40% reduction in DDoS attack success rate in the best cases when compared to the traditional periodic migration schemes on homogeneous cloud resources. The results also show that our market-driven migration location selection strategy decreases CSP cost and increases resource utilization by 30%.
机译:随着DDOS攻击的增加,资源适应方案需要有效地保护关键的云托管应用程序。具体而言,他们需要适应攻击行为,并且在资源利用方面是动态的。在本文中,我们提出了一种智能战略,通过利用“移动目标防御”(MTD)的概念来提出主动和反应申请迁移。我们的方法的新颖性在于:(a)异构云资源的随机主动迁移频率最小化,以优化迁移管理开销,(b)在主动迁移期间优化市场驱动的迁移位置选择,以优化资源利用,云服务提供商(CSP)成本和用户体验质量,(c)快速融合成本最小化的反应迁移耦合,与“错误现实”借口,以减少未来的攻击成功概率。我们使用已启用的软件定义的网络(SDN)的Geni Cloud验证了我们所提出的基于MTD的防御策略的效力,以获得“即时新闻文章和视频源”应用程序。与均匀云资源的传统定期移民计划相比,我们的频率最小化结果显示在最佳情况下,DDOS攻击成功率降低了40%以上。结果还表明,我们的市场驱动的迁移位置选择策略降低了CSP成本,并将资源利用率提高了30%。

著录项

  • 来源
  • 作者单位

    CUNY Dept Comp Sci New York NY 10017 USA|Univ Missouri Dept Elect Engn & Comp Sci Columbia MO 65211 USA|Khalifa Univ Dept Comp Engn Abu Dhabi U Arab Emirates;

    CUNY Dept Comp Sci New York NY 10017 USA|Univ Missouri Dept Elect Engn & Comp Sci Columbia MO 65211 USA|Khalifa Univ Dept Comp Engn Abu Dhabi U Arab Emirates;

    CUNY Dept Comp Sci New York NY 10017 USA|Univ Missouri Dept Elect Engn & Comp Sci Columbia MO 65211 USA|Khalifa Univ Dept Comp Engn Abu Dhabi U Arab Emirates;

    CUNY Dept Comp Sci New York NY 10017 USA|Univ Missouri Dept Elect Engn & Comp Sci Columbia MO 65211 USA|Khalifa Univ Dept Comp Engn Abu Dhabi U Arab Emirates;

    CUNY Dept Comp Sci New York NY 10017 USA|Univ Missouri Dept Elect Engn & Comp Sci Columbia MO 65211 USA|Khalifa Univ Dept Comp Engn Abu Dhabi U Arab Emirates;

    CUNY Dept Comp Sci New York NY 10017 USA|Univ Missouri Dept Elect Engn & Comp Sci Columbia MO 65211 USA|Khalifa Univ Dept Comp Engn Abu Dhabi U Arab Emirates;

    CUNY Dept Comp Sci New York NY 10017 USA|Univ Missouri Dept Elect Engn & Comp Sci Columbia MO 65211 USA|Khalifa Univ Dept Comp Engn Abu Dhabi U Arab Emirates;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Cloud computing; Quality of experience; Optimization; Cyberattack; Servers; IP networks; Cloud security; DDoS attack; moving target defense; software-defined networking;

    机译:云计算;经验质量;优化;网络攻击;服务器;IP网络;云安全;DDOS攻击;移动目标防御;软件定义的网络;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号