论文标题

使用移动目标防御

Proactive DDoS Attack Mitigation in Cloud-Fog Environment using Moving Target Defense

论文作者

Kansal, Vaishali, Dave, Mayank

论文摘要

分布式拒绝服务(DDOS)攻击是严重的网络攻击,减轻云中的DDOS攻击是正在进行的研究兴趣的话题,这仍然是一个主要的安全挑战。雾计算是用于保护云的云计算的扩展。移动目标防御(MTD)是一种新认可的,主动的安全防御,可用于减轻对云的DDOS攻击。 MTD打算通过不断改变攻击表面以使攻击者混淆。在本文中,提出了一种新型的DDOS缓解框架,以使用MTD技术(CFPM)支持云雾平台。 CFPM在FOG层上应用迁移MTD技术来减轻云中的DDOS攻击。它可以在雾层积极检测所有合法客户的攻击者,并将其与无辜的客户隔离。 CFPM使用有效的请求处理程序来进行负载平衡和攻击者隔离过程,该过程旨在最大程度地减少对云服务器的破坏以及服务雾服务器。此外,通过分析攻击前后系统的行为来评估CFPM的有效性,考虑到不同的情况。这种方法是有效的,因为它使用了支持云环境的MTD技术和雾计算范式的优势。

Distributed Denial of Service (DDoS) attacks are serious cyber attacks and mitigating DDoS attacks in cloud is a topic of ongoing research interest which remains a major security challenge. Fog computing is an extension of cloud computing which has been used to secure cloud. Moving Target Defense (MTD) is a newly recognized, proactive security defense that can be used to mitigate DDoS attacks on cloud. MTD intends to make a system dynamic in nature and uncertain by changing attack surface continuously to confuse attackers. In this paper, a novel DDoS mitigation framework is presented to support Cloud-Fog Platform using MTD technique (CFPM). CFPM applies migration MTD technique at fog layer to mitigate DDoS attacks in cloud. It detects attacker among all the legitimate clients proactively at the fog layer and isolate it from innocent clients. CFPM uses an effective request handling procedure for load balancing and attacker isolation procedure which aims to minimize disruption to cloud server as well as serving fog servers. In addition, effectiveness of CFPM is evaluated by analyzing the behavior of the system before and after attack, considering different possible scenarios. This approach is effective as it uses the advantage of both MTD technique and Fog computing paradigm supporting cloud environment.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源