Advanced Search
    Li Baohui, Xu Kefu, Zhang Peng, Guo Li. pTrace: A Counter Technology of DDoS Attack Source for Controllable Cloud Computing[J]. Journal of Computer Research and Development, 2015, 52(10): 2212-2223. DOI: 10.7544/issn1000-1239.2015.20150577
    Citation: Li Baohui, Xu Kefu, Zhang Peng, Guo Li. pTrace: A Counter Technology of DDoS Attack Source for Controllable Cloud Computing[J]. Journal of Computer Research and Development, 2015, 52(10): 2212-2223. DOI: 10.7544/issn1000-1239.2015.20150577

    pTrace: A Counter Technology of DDoS Attack Source for Controllable Cloud Computing

    • Currently, a growing number of attack sources of distributed denial of service (DDoS) are migrating to cloud computing and bringing a greater security challenge to the whole cyberspace. However, the research on effectively suppressing these attack sources is still deficient. So, this paper proposes a method pTrace to defeat the DDoS attack sources in cloud, which comprising the packet filter module inFilter and the malicious process retroactive module mpTrace. inFilter mainly filters packets with forged source address. And, mpTrace firstly identifies attack streams and their corresponding source addresses, then trace malicious processes based on the obtained source addresses. We have implemented a prototype system under Openstack and Xen environment. Experimental results and analysis show that inFilter can prevent large-scale DDoS attack frombeing launched in cloud center with lower time consumption, and mpTrace can identify a attack flow correctly when its flow rate is about 2.5 times the normal traffic, tracing malicious processes in ms time level. At last, this method reduces the impact both on puppet cloud tenant and the victim outside cloud.
    • loading

    Catalog

      Turn off MathJax
      Article Contents

      /

      DownLoad:  Full-Size Img  PowerPoint
      Return
      Return