Title :
A DDoS Mitigation System with Multi-stage Detection and Text-Based Turing Testing in Cloud Computing
Author :
Huang, V.S. ; Huang, R. ; Ming Chiang
Author_Institution :
Cloud Comput. Center for Mobile Applic., Indistrial Technol. Res. Inst., Hsinchu, Taiwan
Abstract :
An important trend in the computer science is towards Cloud Computing and we can see that many cloud services are proposed and developed in the Internet. An important cloud service like the IaaS as AWS EC2 can help many companies to build data centers with high performance computing resources and reduce the cost of maintaining the computing hardware. A data center which provides internet service may suffer from many security risks including Distributed Denial of Service (DDOS) attack. We believe that most of the cloud services, like Gmail, Drop box, Google Document, and etc., are based on HTTP connection. Hence, we aim at HTTP-based connection and propose a low reflection ratio mitigation system against the DDoS attacks. Our system is in the front of an IaaS that all of the virtual data centers in the IaaS are our protection targets. Our system consists of Source Checking, Counting, Attack Detection, Turing Test, and Question Generation modules. We provide a multi-stage detection to more precisely detect the possible attackers and a text-based turing test with question generation module to challenge the suspected requesters who are detected by the detection module. We implemented the proposed system and evaluated the performance to show that our system works efficiently to mitigate the DDoS traffic from the Internet.
Keywords :
Turing machines; authorisation; cloud computing; AWS EC2; DDoS mitigation system; DDoS traffic; HTTP connection; IaaS; Internet; attack detection; cloud computing; cloud services; counting; data center; distributed denial-of-service attack; high performance computing; multistage detection; question generation module; reflection ratio mitigation system; security risk; source checking; text-based Turing testing; Bandwidth; CAPTCHAs; Cloud computing; Computer crime; IP networks; Servers; CAPTCHA; Cloud Computing; DDoS; Multi-Stage Detection; Text-based Question; Turing Testing;
Conference_Titel :
Advanced Information Networking and Applications Workshops (WAINA), 2013 27th International Conference on
Conference_Location :
Barcelona
Print_ISBN :
978-1-4673-6239-9
Electronic_ISBN :
978-0-7695-4952-1
DOI :
10.1109/WAINA.2013.94