DocumentCode :
2182495
Title :
Controlled Virtual Resource Access to Mitigate Economic Denial of Sustainability (EDoS) Attacks against Cloud Infrastructures
Author :
Baig, Zubair A. ; Binbeshr, Farid
Author_Institution :
Dept. of Comput. Eng., King Fahd Univ. of Pet. & Miner., Dhahran, Saudi Arabia
fYear :
2013
fDate :
16-19 Dec. 2013
Firstpage :
346
Lastpage :
353
Abstract :
Service providers of the cloud have witnessed a rapidly growing demand to provide services to end-users in a timely manner. Security vulnerabilities against the cloud infrastructure cannot be overlooked. Through exploitation of such weaknesses, the adversary class may disrupt routine cloud operations, and have a debilitating effect on the reputation of the service provider. One attack type specifically affecting cloud services is the Economic Denial of Sustainability (EDoS) attack. Through such a malicious attack, the ability of the service provider to dynamically stretch and accommodate increasing numbers of requests from end-users, is exploited, to make it economically unviable for the service provider to sustain further demand for service from legitimate end-users. In this paper, we propose a novel approach for selectively controlling user requests for service, implemented at the service provider´s end. Through this scheme, we reduce i.e mitigate the effects of an imminent EDoS attack against critical cloud resources. Incoming requests are classified into normal or suspicious. Subsequently, further analysis is conducted to ensure that priority to cloud service access is given to those end-users tagged as being legitimate, whereas, suspect users are given lesser priority to service access, until they are eventually removed from the suspect list. Simulations were conducted to study the performance of the scheme, with results showing promise.
Keywords :
cloud computing; security of data; EDoS attack; cloud infrastructures; cloud service access; controlled virtual resource access; economic denial of sustainability attacks; malicious attack; service providers; Cloud computing; Computer crime; Delays; Economics; IP networks; Observers; Servers; EDoS Attacks; Firewalls; Rate Control;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Cloud Computing and Big Data (CloudCom-Asia), 2013 International Conference on
Conference_Location :
Fuzhou
Print_ISBN :
978-1-4799-2829-3
Type :
conf
DOI :
10.1109/CLOUDCOM-ASIA.2013.51
Filename :
6821014
Link To Document :
بازگشت