Design a Hybrid Flooding Attack Defense Scheme under the Cloud Computing Environment

Shin-Jer Yang,Hsiao-Ling Huang
DOI: https://doi.org/10.1109/icis46139.2019.8940313
2019-06-01
Abstract:Cloud computing is integrated lots of computing resources which are provided to users over the Internet on a Pay-As-You-Go mode. While multi-tenants and resources sharing are its advantages under the cloud computing environment, it also brings new risks in information security. One of the more difficult consequences of an attack is a flooding attack. This attack is to exhaust the network bandwidth and the computing resources of the server, causing the server to fail to provide services due to heavy workload and may affect the normal service. Other servers in the same infrastructure cause unpredictable losses. Based on the existing DDoS detection technology, this paper proposes a prevention mechanism based on feature selection and random forest classification models to detect hybrid flooding attacks, called HFADS. The HFADS scheme is mainly divided into three modules: (1) Resource Monitor Module (2) Data Features Selection Module (3) Machine Learning Evaluation Module. Based on the above three modules, we perform some simulations for HFADS to be compared with Mouhammd Alkasassbeh et al.'s method to detect flooding attacks of DDoS in terms of three KPIs including recall rate, accuracy rate and average processing time. The final experimental results indicate that HFADS can achieve 99.99% for UDP, 99.95% for ICMP and 99.99% for HTTP in recall rate, 99.98% in accuracy rate and 65.34 seconds in average processing time. Consequently, the proposed HFADS is more effective and efficient than Mouhammd Alkasassbeh et al.'s method for the identification of hybrid flooding attacks.
What problem does this paper attempt to address?