SEYARN: Enhancing Security of YARN Clusters Based on Health Check Service

被引:0
|
作者
Li, Wenting [1 ]
Shen, Qingni [1 ]
Dong, Chuntao [1 ]
Yang, Yahui [1 ]
Wu, Zhonghai [1 ]
机构
[1] Peking Univ, Sch Software & Microelect, MoE Key Lab Network & Software Assurance, Beijing, Peoples R China
基金
中国国家自然科学基金;
关键词
DDoS; Hadoop; YARN; Security;
D O I
10.1007/978-3-319-54433-5_9
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Hadoop serves as an essential tool in the rise of big data, it has insufficient security model. The internal attacks can bypass current Hadoop security mechanism, and compromised Hadoop components can be used to threaten overall Hadoop. This paper studies the vulnerabilities of Health Check Service in Hadoop/YARN and the threat of denial-of-service to a YARN cluster with multi-tenancy. We use theoretical analysis and numerical simulations to demonstrate the effectiveness of this DDoS attack based on health check service (DDHCS). Our experiments show that DDHCS is capable of causing significant impacts on the performance of a YARN cluster in terms of high attack broadness (averagely 85.6%), high attack strength (more than 80%). In addition, we developed a security enhancement for YARN, named SEYARN. We have implemented the SEYARN model, and demonstrated that SEYARN fixes the above vulnerabilities with extending 95% accuracy and minimal run-time overhead, and effectively resists related attacks.
引用
收藏
页码:148 / 168
页数:21
相关论文
共 50 条
  • [1] A Security Service for Enhancing ESB based Execution Platform
    Zhang, Meina
    Zhang, Yang
    Chen, Junliang
    2012 INTERNATIONAL CONFERENCE ON APPLIED INFORMATICS AND COMMUNICATION (ICAIC 2012), 2013, : 122 - 130
  • [2] Enhancing Distributed Web Security Based on Kerberos Authentication Service
    Cao Lai-Cheng
    WEB INFORMATION SYSTEMS AND MINING, 2010, 6318 : 171 - 178
  • [3] Service Realizability Check as a Technique to Support a Service Security Assurance Case
    Filipovikj, Predrag
    Causevic, Aida
    Lisova, Elena
    2020 IEEE INTERNATIONAL CONFERENCE ON INDUSTRIAL TECHNOLOGY (ICIT), 2020, : 973 - 980
  • [4] Security check service and practical technique based on smart grid dispatching and control systems
    Lyu, Ying
    Lu, Guangming
    Yang, Junfeng
    Cheng, Yun
    Luo, Zhiqiang
    Xie, Chang
    Zhou, Jieying
    Deng, Yong
    Dianli Xitong Zidonghua/Automation of Electric Power Systems, 2015, 39 (01): : 171 - 176
  • [5] ISCS (information security check service) for the safety and reliability of the information and communication service
    Suh, Jung-Hoon
    Lee, Jin-Tae
    Jang, Sang-Su
    Lee, Jae-Il
    INTERNET & INFORMATION SYSTEMS IN THE DIGITAL AGE: CHALLENGES AND SOLUTIONS, 2006, : 235 - 238
  • [6] ISCS (Information Security Check Service) for the Safety and Reliability of Communications
    Shin, Jong-Whoi
    Lee, Jin-Tae
    Jang, Sang-Soo
    Lee, Jae-Il
    PROCEEDINGS OF WORLD ACADEMY OF SCIENCE, ENGINEERING AND TECHNOLOGY, VOL 6, 2005, : 22 - 25
  • [7] Security in the Metro de Madrid baggage check-in service
    Garrido, Aurelio Rojo
    Public Transport International, 2006, 55 (01):
  • [8] Enhancing safety and security in a dynamic rideshare service
    Ihinosen, Ariyo Blessing
    Mhlanga, Sandile Thamie
    Lall, Manoj
    PROCEEDINGS OF THE 2020 5TH INTERNATIONAL CONFERENCE ON COMPUTING, COMMUNICATION AND SECURITY (ICCCS-2020), 2020,
  • [9] A Check and Alert Service based on IoT
    Jang, Jae J.
    Kim, Jinseong
    Jung, Im Y.
    2015 IEEE CONFERENCE ON TECHNOLOGIES FOR SUSTAINABILITY (SUSTECH), 2015, : 113 - 116
  • [10] Denial-of-Service Threat to Hadoop/YARN Clusters with Multi-Tenancy
    Huang, Jingwei
    Nicol, David M.
    Campbell, Roy H.
    2014 IEEE INTERNATIONAL CONGRESS ON BIG DATA (BIGDATA CONGRESS), 2014, : 48 - 55