SEYARN: Enhancing Security of YARN Clusters Based on Health Check Service

被引:0
|
作者
Li, Wenting [1 ]
Shen, Qingni [1 ]
Dong, Chuntao [1 ]
Yang, Yahui [1 ]
Wu, Zhonghai [1 ]
机构
[1] Peking Univ, Sch Software & Microelect, MoE Key Lab Network & Software Assurance, Beijing, Peoples R China
基金
中国国家自然科学基金;
关键词
DDoS; Hadoop; YARN; Security;
D O I
10.1007/978-3-319-54433-5_9
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Hadoop serves as an essential tool in the rise of big data, it has insufficient security model. The internal attacks can bypass current Hadoop security mechanism, and compromised Hadoop components can be used to threaten overall Hadoop. This paper studies the vulnerabilities of Health Check Service in Hadoop/YARN and the threat of denial-of-service to a YARN cluster with multi-tenancy. We use theoretical analysis and numerical simulations to demonstrate the effectiveness of this DDoS attack based on health check service (DDHCS). Our experiments show that DDHCS is capable of causing significant impacts on the performance of a YARN cluster in terms of high attack broadness (averagely 85.6%), high attack strength (more than 80%). In addition, we developed a security enhancement for YARN, named SEYARN. We have implemented the SEYARN model, and demonstrated that SEYARN fixes the above vulnerabilities with extending 95% accuracy and minimal run-time overhead, and effectively resists related attacks.
引用
收藏
页码:148 / 168
页数:21
相关论文
共 50 条
  • [41] Serverless-like platform for container-based YARN clusters
    Castellanos-Rodriguez, Oscar
    Exposito, Roberto R.
    Enes, Jonatan
    Taboada, Guillermo L.
    Tourino, Juan
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2024, 155 : 256 - 271
  • [42] An efficient algorithm of service discovery based on service clusters
    Du, Y.Y., 1600, Academic Journals Inc. (08):
  • [43] RETRACTED ARTICLE: Group hash function-based enhancing network security for network service providence
    R. Bharanidharan
    R. Santhosh
    Soft Computing, 2019, 23 : 8495 - 8502
  • [44] Retraction Note: Group hash function-based enhancing network security for network service providence
    R. Bharanidharan
    R. Santhosh
    Soft Computing, 2023, 27 : 1835 - 1835
  • [45] Zoonotic Disease Programs for Enhancing Global Health Security
    Belay, Ermias D.
    Kile, James C.
    Hall, Aron J.
    Barton-Behravesh, Casey
    Parsons, Michele B.
    Salyer, Stephanie
    Walke, Henry
    EMERGING INFECTIOUS DISEASES, 2017, 23 : S65 - S70
  • [46] Enhancing nutritional security and sustainable health through millets
    Ray, Suman
    Gore, Manish Mohan
    Kumar, Ravi Roshan
    Husain, Ayaan
    Sharma, Rupali
    CURRENT SCIENCE, 2024, 126 (08): : 874 - 875
  • [47] Security Check of Scheduling Plan Based on Shared Computing Resources
    Lü, Ying
    Jia, Yupei
    Luo, Zhiqiang
    He, Chunjiang
    Ji, Shijie
    Yu, Zhihong
    Chang, Naichao
    Dianwang Jishu/Power System Technology, 2021, 45 (02): : 596 - 604
  • [48] Enhancing Experiment Central Service Reliability: from delivery to security and virtualization
    Donno, F.
    Baranov, S.
    Buzykaev, S.
    Santos, M. D. Saiz
    INTERNATIONAL CONFERENCE ON COMPUTING IN HIGH ENERGY AND NUCLEAR PHYSICS (CHEP 2010), 2011, 331
  • [50] Soundness analysis of logic service net based on service clusters
    Du, YuYue
    Hu, Qiang
    Journal of Software Engineering, 2013, 7 (01): : 30 - 38