Beenish Habib, Farida Khurshid, A. Dar, Zubair Shah
{"title":"DDoS Mitigation in Eucalyptus Cloud Platform Using Snort and Packet Filtering — IP-Tables","authors":"Beenish Habib, Farida Khurshid, A. Dar, Zubair Shah","doi":"10.1109/ISCON47742.2019.9036183","DOIUrl":null,"url":null,"abstract":"Cloud Computing is technologically the emerging trend of providing computational resources on demand, may that be storage, network or computation, it encompasses all. The resources can be provided by private, public or a hybrid cloud. Cloud computing is the future of computing and is struggling with the concern of security. Among all security concerns, the Distributed Denial of Service (DDoS) attack is one of the biggest threats to both Internet Security and to Cloud as well. A sizable amount of bots is indulged in the creation of DDoS attacks on a Cloud target by flooding them with malformed packets to exhaust the resources. On the other hand, Economic Denial of Sustainability (EDoS) is a new threat to Cloud security which exploits the cloud elasticity and auto-scaling features and charges the user way too high; thus making economically a theft in it. Public cloud is less prone to attacks as they have inbuilt load balancers and mitigation setups. A private cloud like Eucalyptus is more vulnerable to DDoS attacks as they have lesser defense setups. To overcome these issues we propose a system of DDoS mitigation using Snort for DDoS detection and Packet Filtering IP-Tables in Private cloud set up of Eucalyptus. It acts as our defensive front. This way, our cloud gets saved from DDoS attack without it being burdened with the excess traffic.","PeriodicalId":124412,"journal":{"name":"2019 4th International Conference on Information Systems and Computer Networks (ISCON)","volume":"25 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2019-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"5","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2019 4th International Conference on Information Systems and Computer Networks (ISCON)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ISCON47742.2019.9036183","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 5
Abstract
Cloud Computing is technologically the emerging trend of providing computational resources on demand, may that be storage, network or computation, it encompasses all. The resources can be provided by private, public or a hybrid cloud. Cloud computing is the future of computing and is struggling with the concern of security. Among all security concerns, the Distributed Denial of Service (DDoS) attack is one of the biggest threats to both Internet Security and to Cloud as well. A sizable amount of bots is indulged in the creation of DDoS attacks on a Cloud target by flooding them with malformed packets to exhaust the resources. On the other hand, Economic Denial of Sustainability (EDoS) is a new threat to Cloud security which exploits the cloud elasticity and auto-scaling features and charges the user way too high; thus making economically a theft in it. Public cloud is less prone to attacks as they have inbuilt load balancers and mitigation setups. A private cloud like Eucalyptus is more vulnerable to DDoS attacks as they have lesser defense setups. To overcome these issues we propose a system of DDoS mitigation using Snort for DDoS detection and Packet Filtering IP-Tables in Private cloud set up of Eucalyptus. It acts as our defensive front. This way, our cloud gets saved from DDoS attack without it being burdened with the excess traffic.