Title
DDoS victim service containment to minimize the internal collateral damages in cloud computing.
Abstract
Recent Distributed Denial of Service (DDoS) attacks on cloud services demonstrate new attack effects, including collateral and economic losses. In this work, we show that DDoS mitigation methods may not provide the expected timely mitigation due to the heavy resource outage created by the attacks. We observe an important Operating System (OS) level “internal collateral damage”, in which the other critical services are also affected. We formulate the DDoS mitigation problem as an OS level resource management problem. We argue that providing extra resources to the victim’s server is only helpful if we can ensure the availability of other services. To achieve these goals, we propose a novel resource containment approach to enforce the victim’s resource limits. Our real-time experimental evaluations show that the proposed approach results in reduction in the attack reporting time and victim service downtime by providing isolated and timely resources to ensure availability of other critical services.
Year
DOI
Venue
2017
10.1016/j.compeleceng.2016.12.004
Computers & Electrical Engineering
Keywords
Field
DocType
Cloud computing,Cloud security,Distributed Denial of Service (DDoS) attack and Economic Denial of Sustainability (EDoS) attack
Resource management,Denial-of-service attack,Computer science,Computer security,Trinoo,Computer network,Cloud computing security,DDoS mitigation,Downtime,Application layer DDoS attack,Cloud computing
Journal
Volume
ISSN
Citations 
59
0045-7906
1
PageRank 
References 
Authors
0.36
10
5
Name
Order
Citations
PageRank
Gaurav Somani117711.85
Manoj S. Gaur250163.38
Dheeraj Sanghi3224109.20
Mauro Conti42430203.80
Muttukrishnan Rajarajan559361.50