WEBTRAP: A Dynamic Defense Scheme Against Economic Denial of Sustainability Attacks

被引:0
|
作者
Wang, Huangxin [1 ]
Xi, Zhonghua [1 ]
Li, Fei [1 ]
Chen, Songqing [1 ]
机构
[1] George Mason Univ, Fairfax, VA 22030 USA
来源
2017 IEEE CONFERENCE ON COMMUNICATIONS AND NETWORK SECURITY (CNS) | 2017年
关键词
DDOS DEFENSE;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Economic Denial of Sustainability (EDoS) attacks have been threatening cloud consumers' financial viability due to the "pay-as-you-go" cloud resource charging scheme. EDoS attackers can take advantage of this pricing scheme to fraudulently consume the billable cloud resources from the cloud consumers and thus, drive up the cloud consumers' financial cost and eventually disrupt their economic sustainability. In this paper, we propose WEBTRAP, a defense scheme against EDoS attacks for web-based systems. WEBTRAP consists of two major components. On one side, it dynamically changes/updates web resource addresses so that the web-based system is equipped with a moving target defense capability to make attackers unable to exploit web resources. On the other side, WEBTRAP injects carefully-designed traps in a real-time manner to detect attackers. The trap injection process is guided by an online control-based algorithm to balance the damage introduced by the attackers and the potential side-impacts on benign clients and minimize the overall cost. We conduct experiments to validate WEBTRAP's effectiveness under various types of websites. The evaluation results demonstrate that WEBTRAP is effective, by more than 80%, in reducing the cost suffered by the cloud consumers.
引用
收藏
页码:55 / 63
页数:9
相关论文
共 50 条
  • [31] Economic Incentive based Solution against Distributed Denial of Service Attacks for IoT Customers
    Adat, Vipindev
    Dahiya, Amrita
    Gupta, B. B.
    2018 IEEE INTERNATIONAL CONFERENCE ON CONSUMER ELECTRONICS (ICCE), 2018,
  • [32] A Periodic Event-Triggered Vehicle Platooning Scheme Against Denial-of-Service Attacks
    Liu, Jingxuan
    Ding, Sanbo
    Jing, Yanhui
    Xie, Xiangpeng
    IEEE TRANSACTIONS ON INTELLIGENT VEHICLES, 2024, 9 (01): : 839 - 851
  • [33] A THREE-LAYER DEFENSE MECHANISM BASED ON WEB SERVERS AGAINST DISTRIBUTED DENIAL OF SERVICE ATTACKS
    Wu, Zhijun
    Chen, Zhifeng
    2006 FIRST INTERNATIONAL CONFERENCE ON COMMUNICATIONS AND NETWORKING IN CHINA, 2006,
  • [34] Reputation-based defense scheme against pollution attacks on network coding
    Wang T.
    Cai Y.
    Zhang Y.
    Jisuanji Yanjiu yu Fazhan/Computer Research and Development, 2016, 53 (11): : 2491 - 2499
  • [35] D-WARD: A source-end defense against flooding denial-of-service attacks
    Mirkovic, J
    Reiher, P
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2005, 2 (03) : 216 - 232
  • [36] An Efficient Defense Method against UDP Spoofed Flooding Traffic of Denial of Service (DoS) Attacks in VANET
    Verma, Karan
    Hasbullah, Halabi
    Kumar, Ashok
    PROCEEDINGS OF THE 2013 3RD IEEE INTERNATIONAL ADVANCE COMPUTING CONFERENCE (IACC), 2013, : 550 - 555
  • [37] Defending networks against denial of service attacks
    Gelenbe, E
    Gellman, M
    Loukas, G
    UNMANNED/UNATTENDED SENSORS AND SENSOR NETWORKS, 2004, 5611 : 233 - 243
  • [38] Defending against denial of service attacks in scout
    Spatscheck, O
    Peterson, LL
    USENIX ASSOCIATION PROCEEDINGS OF THE THIRD SYMPOSIUM ON OPERATING SYSTEMS DESIGN AND IMPLEMENTATION (OSDI '99), 1999, : 59 - 72
  • [39] Protection Against Denial of Service Attacks: A Survey
    Loukas, Georgios
    Oke, Gulay
    COMPUTER JOURNAL, 2010, 53 (07): : 1020 - 1037
  • [40] Countermeasures against Distributed Denial of Service attacks
    Stefanidis, K.
    Serpanos, D. N.
    2005 IEEE INTELLIGENT DATA ACQUISITION AND ADVANCED COMPUTING SYSTEMS: TECHNOLOGY AND APPLICATIONS, 2005, : 439 - 442