An Efficient DDoS TCP Flood Attack Detection and Prevention System in a Cloud Environment

被引:80
|
作者
Sahi, Aqeel [1 ,2 ]
Lai, David [2 ]
Li, Yan [2 ]
Diykh, Mohammed [1 ,2 ]
机构
[1] Thi Qar Univ, Nasiriya 64001, Iraq
[2] Univ Southern Queensland, Sch Agr Computat & Environm Sci, Toowoomba, Qld 4350, Australia
来源
IEEE ACCESS | 2017年 / 5卷
关键词
Classification; cloud computing; DDoS attacks; LS-SVM; CLASSIFICATION; ALGORITHM; DEFENSE; DOS;
D O I
10.1109/ACCESS.2017.2688460
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Although the number of cloud projects has dramatically increased over the last few years, ensuring the availability and security of project data, services, and resources is still a crucial and challenging research issue. Distributed denial of service (DDoS) attacks are the second most prevalent cybercrime attacks after information theft. DDoS TCP flood attacks can exhaust the cloud's resources, consume most of its bandwidth, and damage an entire cloud project within a short period of time. The timely detection and prevention of such attacks in cloud projects are therefore vital, especially for eHealth clouds. In this paper, we present a new classifier system for detecting and preventing DDoS TCP flood attacks (CS_DDoS) in public clouds. The proposed CS_DDoS system offers a solution to securing stored records by classifying the incoming packets and making a decision based on the classification results. During the detection phase, the CS_DDOS identifies and determines whether a packet is normal or originates from an attacker. During the prevention phase, packets, which are classified as malicious, will be denied to access the cloud service and the source IP will be blacklisted. The performance of the CS_DDoS system is compared using the different classifiers of the least squares support vector machine (LS-SVM), naive Bayes, K-nearest, and multilayer perceptron. The results show that CS_DDoS yields the best performance when the LS-SVM classifier is adopted. It can detect DDoS TCP flood attacks with about 97% accuracy and with a Kappa coefficient of 0.89 when under attack from a single source, and 94% accuracy with a Kappa coefficient of 0.9 when under attack from multiple attackers. Finally, the results are discussed in terms of accuracy and time complexity, and validated using a K-fold cross-validation model.
引用
收藏
页码:6036 / 6048
页数:13
相关论文
共 50 条
  • [1] Efficient DDoS attack detection and prevention scheme based on SDN in cloud environment
    He H.
    Hu Y.
    Zheng L.
    Xue Z.
    [J]. He, Heng (heheng@wust.edu.cn), 2018, Editorial Board of Journal on Communications (39): : 139 - 151
  • [2] An Efficient system to stumble on and Mitigate DDoS attack in cloud Environment
    Mohan, Manju K.
    [J]. PROCEEDINGS OF THE 2018 SECOND INTERNATIONAL CONFERENCE ON INVENTIVE COMMUNICATION AND COMPUTATIONAL TECHNOLOGIES (ICICCT), 2018, : 1855 - 1857
  • [3] Intrusion Detection System-An Efficient way to Thwart against Dos/DDos Attack in the Cloud Environment
    Aishwarya, R.
    Malliga, S.
    [J]. 2014 INTERNATIONAL CONFERENCE ON RECENT TRENDS IN INFORMATION TECHNOLOGY (ICRTIT), 2014,
  • [4] TCP/IP Header Classification for Detecting Spoofed DDoS Attack in Cloud Environment
    Osanaiye, Opeyemi. A.
    Dlodlo, Mqhele
    [J]. IEEE EUROCON 2015 - INTERNATIONAL CONFERENCE ON COMPUTER AS A TOOL (EUROCON), 2015, : 219 - 224
  • [5] TCP and HTTP Flood DDOS Attack Analysis and Detection for space ground Network
    Shaaban, Eng Ahmed Ramzy
    Abdelwaness, Essam
    Hussein, Mohamed
    [J]. 2019 IEEE INTERNATIONAL CONFERENCE OF VEHICULAR ELECTRONICS AND SAFETY (ICVES 19), 2019,
  • [6] An efficient DDoS attack detection mechanism in SDN environment
    Hnamte V.
    Hussain J.
    [J]. International Journal of Information Technology, 2023, 15 (5) : 2623 - 2636
  • [7] DDoS Attack Detection and Mitigation Techniques in Cloud Computing Environment
    Devi, Kiruthika B. S.
    Subbulakshmi, T.
    [J]. PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON INTELLIGENT SUSTAINABLE SYSTEMS (ICISS 2017), 2017, : 512 - 517
  • [8] Detection Mechanisms of DDoS Attack in Cloud Computing Environment: A Survey
    Alarqan, Mohammad Abdelkareem
    Zaaba, Zarul Fitri
    Almomani, Ammar
    [J]. ADVANCES IN CYBER SECURITY (ACES 2019), 2020, 1132 : 138 - 152
  • [9] Effective Detection and Prevention of DDoS in Cloud Computing Environment
    Tajane, Vrushali
    Sharma, Deepak
    [J]. 2018 FOURTH INTERNATIONAL CONFERENCE ON COMPUTING COMMUNICATION CONTROL AND AUTOMATION (ICCUBEA), 2018,
  • [10] Design of TCP SYN Flood DDoS Attack Detection Using Artificial Immune Systems
    Ramadhan, Gilang
    Kurniawan, Yusuf
    Kim, Chang-Soo
    [J]. PROCEEDINGS OF THE 2016 6TH INTERNATIONAL CONFERENCE ON SYSTEM ENGINEERING AND TECHNOLOGY (ICSET), 2016, : 72 - 76