Title
Toward a Source Detection of Botclouds: A PCA-Based Approach.
Abstract
Cloud computing security is often focused on data and users security and protection against external intrusions. However, it exists an area of cloud security that is often overlooked and that can have disastrous consequences: the conversion of cloud computing into an attack vector. Beyond a legitimate usage, the numerous advantages of cloud computing are exploited by attackers. Botnets supporting Distributed Denial of Service (DDoS) attacks are among the greatest beneficiaries of this malicious use. In this paper, we propose a novel source-based detection approach that aims at detecting the abnormal virtual machines behavior. The originality of our approach resides in (1) relying only on the system's metrics of virtual machines and (2) considering a source-based detection. Our approach is based on Principal Component Analysis to detect anomalies that can be signs of botcloud's behavior supporting DDoS flooding attacks. We also present the results of the evaluation of our detection algorithm.
Year
DOI
Venue
2014
10.1007/978-3-662-43862-6_13
Lecture Notes in Computer Science
Field
DocType
Volume
Virtual machine,Denial-of-service attack,Botnet,Computer science,Originality,Cloud computing security,Intrusion detection system,Principal component analysis,Distributed computing,Cloud computing
Conference
8508
ISSN
Citations 
PageRank 
0302-9743
1
0.37
References 
Authors
13
3
Name
Order
Citations
PageRank
Badis Hammi1696.57
Guillaume Doyen29813.25
Rida Khatoun312217.66