SEYARN: Enhancing Security of YARN Clusters Based on Health Check Service

被引:0
|
作者
Li, Wenting [1 ]
Shen, Qingni [1 ]
Dong, Chuntao [1 ]
Yang, Yahui [1 ]
Wu, Zhonghai [1 ]
机构
[1] Peking Univ, Sch Software & Microelect, MoE Key Lab Network & Software Assurance, Beijing, Peoples R China
基金
中国国家自然科学基金;
关键词
DDoS; Hadoop; YARN; Security;
D O I
10.1007/978-3-319-54433-5_9
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Hadoop serves as an essential tool in the rise of big data, it has insufficient security model. The internal attacks can bypass current Hadoop security mechanism, and compromised Hadoop components can be used to threaten overall Hadoop. This paper studies the vulnerabilities of Health Check Service in Hadoop/YARN and the threat of denial-of-service to a YARN cluster with multi-tenancy. We use theoretical analysis and numerical simulations to demonstrate the effectiveness of this DDoS attack based on health check service (DDHCS). Our experiments show that DDHCS is capable of causing significant impacts on the performance of a YARN cluster in terms of high attack broadness (averagely 85.6%), high attack strength (more than 80%). In addition, we developed a security enhancement for YARN, named SEYARN. We have implemented the SEYARN model, and demonstrated that SEYARN fixes the above vulnerabilities with extending 95% accuracy and minimal run-time overhead, and effectively resists related attacks.
引用
收藏
页码:148 / 168
页数:21
相关论文
共 50 条
  • [31] Involving the elderly in the content development of a health enhancing tablet-based service
    Kuoremaki, Reija
    Poskiparta, Marita
    Neittaanmaki, Pekka
    2014 EAI 4TH INTERNATIONAL CONFERENCE ON WIRELESS MOBILE COMMUNICATION AND HEALTHCARE (MOBIHEALTH), 2014, : 28 - 31
  • [32] Evidence-based health check
    Plaza, Martin
    Manzanares, Sebastian
    Cordero, Maria Jose
    REVISTA MEDICA CLINICA LAS CONDES, 2021, 32 (04): : 379 - 390
  • [33] Enhancing Cloud Security and Privacy: Broadening the Service Level Agreement
    Duncan, Bob
    Whittington, Mark
    2015 IEEE TRUSTCOM/BIGDATASE/ISPA, VOL 1, 2015, : 1088 - 1093
  • [34] Enhancing Internet service security using GSM SIM authentication
    van Thanh, Do
    Jonvik, Tore
    van Thuan, Do
    Jorstad, Ivar
    GLOBECOM 2006 - 2006 IEEE GLOBAL TELECOMMUNICATIONS CONFERENCE, 2006,
  • [35] A Proposal for Enhancing The Security System of Short Message Service in GSM
    Hossain, Md. Asif
    Jahan, Sarwar
    Hussain, M. M.
    Amin, M. R.
    Newaz, S. H. Shah
    2008 2ND INTERNATIONAL CONFERENCE ON ANTI-COUNTERFEITING, SECURITY AND IDENTIFICATION, 2008, : 235 - +
  • [36] Enhancing OAuth Services Security by an Authentication Service with Face Recognition
    Alotaibi, Aziz
    Mahmmod, Ausif
    2015 IEEE LONG ISLAND SYSTEMS, APPLICATIONS AND TECHNOLOGY CONFERENCE (LISAT), 2015,
  • [37] Substitution and analysis of service composition based on service clusters
    Du, Yu-Yue
    Xue, Jie
    Li, Yan-Cheng
    Tien Tzu Hsueh Pao/Acta Electronica Sinica, 2014, 42 (11): : 2231 - 2238
  • [38] An efficient algorithm of service discovery based on service clusters
    Gai, Jun Jing
    Du, Yu Yue
    Journal of Software Engineering, 2014, 8 (02): : 100 - 107
  • [39] A service selection method based on web service clusters
    Liu, Wei
    Du, Yu-Yue
    Yan, Chun
    Journal of Applied Sciences, 2013, 13 (24) : 5734 - 5738
  • [40] Serverless-like platform for container-based YARN clusters
    Castellanos-Rodríguez, Óscar
    Expósito, Roberto R.
    Enes, Jonatan
    Taboada, Guillermo L.
    Touriño, Juan
    Future Generation Computer Systems, 2024, 155 : 256 - 271