WEBTRAP: A Dynamic Defense Scheme Against Economic Denial of Sustainability Attacks

被引:0
|
作者
Wang, Huangxin [1 ]
Xi, Zhonghua [1 ]
Li, Fei [1 ]
Chen, Songqing [1 ]
机构
[1] George Mason Univ, Fairfax, VA 22030 USA
来源
2017 IEEE CONFERENCE ON COMMUNICATIONS AND NETWORK SECURITY (CNS) | 2017年
关键词
DDOS DEFENSE;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Economic Denial of Sustainability (EDoS) attacks have been threatening cloud consumers' financial viability due to the "pay-as-you-go" cloud resource charging scheme. EDoS attackers can take advantage of this pricing scheme to fraudulently consume the billable cloud resources from the cloud consumers and thus, drive up the cloud consumers' financial cost and eventually disrupt their economic sustainability. In this paper, we propose WEBTRAP, a defense scheme against EDoS attacks for web-based systems. WEBTRAP consists of two major components. On one side, it dynamically changes/updates web resource addresses so that the web-based system is equipped with a moving target defense capability to make attackers unable to exploit web resources. On the other side, WEBTRAP injects carefully-designed traps in a real-time manner to detect attackers. The trap injection process is guided by an online control-based algorithm to balance the damage introduced by the attackers and the potential side-impacts on benign clients and minimize the overall cost. We conduct experiments to validate WEBTRAP's effectiveness under various types of websites. The evaluation results demonstrate that WEBTRAP is effective, by more than 80%, in reducing the cost suffered by the cloud consumers.
引用
收藏
页码:55 / 63
页数:9
相关论文
共 50 条
  • [21] A packet filter placement problem with application to defense against spoofed denial of service attacks
    Armbruster, Benjamin
    Smith, J. Cole
    Park, Kihong
    EUROPEAN JOURNAL OF OPERATIONAL RESEARCH, 2007, 176 (02) : 1283 - 1292
  • [22] Rule-based Defense mechanism against distributed denial-of-service attacks
    Kim, Sung-ju
    Kim, Byung-chul
    Lee, Jae-yong
    Hwang, Chan-kyou
    Lee, Jae-jin
    WORLD CONGRESS ON ENGINEERING 2008, VOLS I-II, 2008, : 543 - +
  • [23] VFence: A Defense against Distributed Denial of Service Attacks using Network Function Virtualization
    Jakaria, A. H. M.
    Yang, Wei
    Rashidi, Bahman
    Fung, Carol
    Rahman, M. Ashigur
    PROCEEDINGS 2016 IEEE 40TH ANNUAL COMPUTER SOFTWARE AND APPLICATIONS CONFERENCE WORKSHOPS (COMPSAC), VOL 2, 2016, : 431 - 436
  • [24] An On-Demand Defense Scheme Against DNS Cache Poisoning Attacks
    Wang, Zheng
    Yu, Shui
    Rose, Scott
    SECURITY AND PRIVACY IN COMMUNICATION NETWORKS, SECURECOMM 2017, 2018, 238 : 793 - 807
  • [25] Dynamic defense against byzantine poisoning attacks in federated learning
    Rodriguez-Barroso, Nuria
    Martinez-Camara, Eugenio
    Victoria Luzon, M.
    Herrera, Francisco
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2022, 133 : 1 - 9
  • [26] Scheme to Prevent Denial of Service Attacks on UPnP
    Wang, Jiahui
    He, Liang
    Zhou, Zili
    2008 ISECS INTERNATIONAL COLLOQUIUM ON COMPUTING, COMMUNICATION, CONTROL, AND MANAGEMENT, VOL 1, PROCEEDINGS, 2008, : 430 - 433
  • [27] An Efficient Defense against Distributed Denial-of-Service Attacks using Congestion Path Marking
    Kim, Yoohwan
    Abd El Al, Ahmed
    Jo, Ju-Yeon
    Yang, Mei
    Jiang, Yingtao
    2006 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, VOLS 1-12, 2006, : 2159 - 2164
  • [28] Defense against low-rate TCP-targeted denial-of-service attacks
    Yang, G
    Gerla, M
    Sanadidi, MY
    ISCC2004: NINTH INTERNATIONAL SYMPOSIUM ON COMPUTERS AND COMMUNICATIONS, VOLS 1 AND 2, PROCEEDINGS, 2004, : 345 - 350
  • [29] Leader: Defense Against Exploit-Based Denial-of-Service Attacks onWeb Applications
    Tandon, Rajat
    Wang, Haoda
    Weideman, Nicolaas
    Arakelyan, Shushan
    Bartlett, Genevieve
    Hauser, Christophe
    Mirkovic, Jelena
    PROCEEDINGS OF THE 26TH INTERNATIONAL SYMPOSIUM ON RESEARCH IN ATTACKS, INTRUSIONS AND DEFENSES, RAID 2023, 2023, : 744 - 758
  • [30] Defense and Monitoring Model for Distributed Denial of Service Attacks
    Tariq, Usman
    Malik, Yasir
    Abdulrazak, Bessam
    ANT 2012 AND MOBIWIS 2012, 2012, 10 : 1052 - 1056