0% found this document useful (0 votes)
35 views8 pages

DDoS Attacks in Cloud Computing: Review

The document reviews Distributed Denial of Service (DDoS) attacks and their countermeasures in cloud computing, highlighting the security challenges posed by such attacks on cloud resources. It categorizes DDoS attacks into various types and discusses potential defense mechanisms, including intrusion detection and prevention strategies. The paper emphasizes the importance of securing cloud infrastructure to maintain resource availability for legitimate users.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
35 views8 pages

DDoS Attacks in Cloud Computing: Review

The document reviews Distributed Denial of Service (DDoS) attacks and their countermeasures in cloud computing, highlighting the security challenges posed by such attacks on cloud resources. It categorizes DDoS attacks into various types and discusses potential defense mechanisms, including intrusion detection and prevention strategies. The paper emphasizes the importance of securing cloud infrastructure to maintain resource availability for legitimate users.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

See discussions, stats, and author profiles for this publication at: [Link]

net/publication/358635409

A Review of DDoS Attacks and its Countermeasures in Cloud Computing

Conference Paper · February 2022


DOI: 10.1109/ISCON52037.2021

CITATIONS READS

0 806

1 author:

Asha varma Songa


Velagapudi Ramakrishna Siddhartha Engineering College
4 PUBLICATIONS 1 CITATION

SEE PROFILE

All content following this page was uploaded by Asha varma Songa on 16 July 2022.

The user has requested enhancement of the downloaded file.


A Review of DDoS Attacks and
Its Countermeasures in Cloud Computing
[Link] Varma [Link] Reddy
School of Computer Science and Engineering School of Computer Science and Engineering
VIT-AP University VIT-AP University
Amaravathi, India Amaravathi, India
ashavarma.20phd7123@[Link] guncity11@[Link]

Abstract— In the present scenario, cloud computing has computing, another important concept is virtualization, which
become a marketable technology that allows consumers to easily allows sharing a single physical instance of a resource to many
access resources through the internet, based on pay per use customers and organizations[2]. As everything is accessible to
model. These resources are provided as services to the customer. users over the internet there is a high risk for the resources to
Infrastructure as a Service, Platform as a Service, and Software be attacked. As a huge amount of data migrate to the cloud,
as a Service are the 3 service models provided by the cloud. criminals are becoming more interested in exploiting cloud
With the huge advancement in cloud computing technologies, it vulnerabilities and stealing critical data. The Distributed Denial of
is widely used by many business applications, industry Service (DDoS) attacks are the major and worst among Ease of
applications, Enterprise organizations that are committing to
Use the several attacks to cloud computing. In a Denial of
multi-cloud architectures, and finally, most IT expenditures are
Service (DoS) attack, the attacker overloads the victim system
based on the cloud. However, security is the key challenge that
needs more concern. According to recent studies, the most
with several flooded requests and makes the system
critical security concern that is confronted by cloud users is unavailable to the legitimate user[3]. DDoS uses a group of
resource availability. This availability issue is mostly affected by infected systems to perform Dos attacks on the system causing
the Distributed Denial of service attack. The Distributed Denial the service unavailable to the legitimate user[4]. The DDoS
of service attack is an enhanced model of Denial of service. The attack mostly assaults the security at the infrastructure level of
main intention behind the Distributed Denial of Service attack is the cloud[5].
to bring down a specific service by flooding the servers and
The Structure of this document is represented as follows:
network with malformed packets which leads to the
unavailability of resources to legitimate users in a cloud.
Section-II discusses the overview of cloud computing and its
Recently, cloud infrastructures also have been severely impacted security issues. Section-III reflects on the DDoS attacks and
by denial of service attacks. The attacker always tries to break their types in Cloud computing. Section-IV deliberates about
the security at the infrastructure level as it provides the basic the different suggested countermeasures of DDoS attacks and
computing infrastructure for all cloud delivery models. This their results. Section-V confronts the Research outcome.
paper frames the cloud computing services and Distributed Section-VI finally the conclusion.
Denial of Service attack scenarios and their different defense
mechanisms. II. CLOUD COMPUTING: OVERVIEW
Keywords— Cloud computing, Cloud Security, DDoS attacks. A. Overview
The global economy has shifted from manufacturing to
I. INTRODUCTION service-oriented during the last two decades. The service
Cloud computing is a pool of resources available at any industry gets the most from cloud computing, and it advances
time and anywhere to the user on pay on demand. The only corporate computing with a new paradigm. Cloud computing
requirement the user needs to have is a proper internet allows the customers to share and access the resources from
connection to use the services from the cloud. The cloud any place and at any time through the connected devices and
service providers will handle all the processing requirements allowing them to collaborate on the projects. Because of the
and so, all the intricacies will be hidden from the user. There cloud’s key services IaaS, PaaS, and SaaS the IT industry got
are several advantages given by the cloud such as the scaling of free from the low-level task of setting up the hardware and
resources when required, remote network access, pooling of managing the Software Furthermore the availability of
resources e.t.c. Infrastructure as a Service(IaaS), Platform as a resources, pilling of datasets, and cost are determined with
Service(PaaS), and Software as a Service(SaaS) are the three required service [6]. Many institutions have moved to cloud
service models provided by the cloud [1]. The cloud also computing due to its potential benefits such as service
provides several benefits such as Self-service delivery, availability and accessibility to resources which decrease the
reliability, social networking, reduced costs, data security and expense to ventures [7]. The NIST defined 5 essential attributes
privacy, scalability, and elasticity, and so on. In cloud of cloud computing as Measured service, Resource pooling,
On-demand self-service, Rapid elasticity, and Broad network services to be secured. When utilizing cloud computing,
access [8]. The Cloud provides the service models and several businesses are more concerned about the safety and
deployment models to the user. The service models are also privacy of the data[9]. There are so many threats and
known as reference models for cloud computing. These may be breaches that perform on cloud computing[10]. A few of
divided into three categories, as follows: them have been specified in Table. I, respectively. The fact
that PaaS and SaaS are placed on top of IaaS means that
1) Infrastructure as a service (IaaS): The customer will be any security compromise in the IaaS might affect the
able to provide the infrastructure computing facilities such as security of both. The SaaS security issues may contain
the processing power, storage, networks, and other basic application security, Accessibility, data security, and Multi-
computing resources. tenancy. The issues with PaaS include Third-party
2) Platform as a service (PaaS): It provides the customer relationships, development lifecycle, underlying
with the runtime environment necessary to develop and deploy infrastructure security. IaaS security issues may include
thesoftware. Virtualization, VM Hypervisor, VM networks, Rollback,
3) Software as a Service (SaaS): With this model, users VM migration, and so on.
can have access to the provider's apps, which are hosted on the TABLE I. CLOUDSECURITY THREATS
cloud architecture.
Threats Explanation
A data breach is where the information is stolen
Data Breaches from the system without the knowledge of the
system’s owner
To provide programmers with APIs, the CSP
API’s are unsafe
employs a particular framework that makes their
systems more vulnerable to attackers. So, CSA
says that APIs should be protected.
Anonymity, End-user companies and CC are both harmed by
credentials, and illegal access to data.
Access
management
Information can be altered or disclosed to third
parties as a result of cloud account hijacking.
Account hijacking
Malicious insiders are the former or current
Malicious insiders employee, contractor, or valued business partner
of a company that exploits their access in a way
that harms the company.
Type of cyber attack which is used to gain
Persistent threats
ongoing access to the system.
Even natural calamities may be one of the
reasons for data loss.
Loss of data
Fig 1. The architecture of Cloud Computing These attacks prevent legitimate users to access
Denial of Service the system by flooding the system with more
The cloud computing architecture with different layers of traffic.
service models is depicted in Figure.1 respectively. A part of
the service models, the cloud deployment models specify the
type of cloud that needs to be accessed and how it is located
III. DDOS ATTACK OVERVIEW
[8]. These are categorized into 4 models as defined below:
1) Public cloud: It enables the general people to have easy A. DDoS Overview: A DoS attack occurs when security is
access to systems and services. breached. It prevents legitimate clients from accessing
2) Private cloud: The deployment model is set up for one targeted cloud systems, devices, or other cloud resources.
organization with several users to use exclusively. A network of Zombies, which are remotely operated, well
3) Hybrid cloud: The cloud infrastructure is made up of structured, and widely distributed nodes execute DDoS
both public and private clouds. attacks. With the help of the zombies called secondary
4) Community cloud: The infrastructure is intended for victims, the attacker initiates the attack. The DDoS attacks
usage by a select group of customers from organizations that are classified into 3 categories [11].
share similar concerns. 1) Volume-based/Bandwidth-based Attacks: This attack
B. Cloud Security Issues: tries to overwhelm the user with a massive volume of garbage
data, using network bandwidth and resourcesin the process.
Security is one of the major challenging issues of 2) Protocol Attacks: The attack attempts to overload the
cloud computing. With the rapid development of cloud target’s resources by exploiting a flaw related to multiple
computing, there is much need for the resources and
network protocols.
3) Application layer attacks: The attack targets certain sender and receiver fields, akin to a ping attack. As a
online apps and delivers HTTP requests that exceed the consequence, the computer sends the requests before shutting
application’s capacity. down.
13) Zero-day attack: The zero-day attack is the threat of the
B. Types of DDoS Attack:
unknown which exploits vulnerabilities without the user’s
Some of the specific DDoS attacks are explained knowledge. It carries huge costs to organizations in the form
below[11]: of system downtime, lost productivity, reputation damage, and
1) UDP flood: A UDP flood is a sort of DoS attack in data theft.
which the targeted host is flooded with IP packets containing a Furthermore, the above-mentioned attacks are classified under
UDP datagram. If no applications have these datagrams, a these 3 categories and are depicted in the following Fig. 2,
destination unreachable packet is sent by the receiving host. respectively.
As more UDP packets are received and responded, the system
gets overburdened and unavailable to other clients.
2) ICMP flood: A ping flood is also known as ICMP
flood, is a typical DDoS attack in which the attacker brings
down a causality’s PC by overpowering it with ICMP echo
requests known as pings.
3) Smurf attack: It is an amplification attack vector that
increases harm potential by leveraging the broadcast network
features.
4) Fraggle attack: It entails flooding a network with faked
UDP traffic directed at a router's broadcast address.
5) TCP SYN attack: It makes use of a portion of the
standard TCP Three-Way handshake to drain resources on the
targeted server and make it unavailable [12].
6) Ping of death: A basic ping command is used by an
attacker to try to stop or crash the targeted computer or
service.
7) HTTP DDoS attack: It is a volumetric DDoS attack that
floods the targeted server with HTTP requests and is unable
to respond to normal traffic.
8) XML DDoS attack: The attacks deplete the server’s
resources and network bandwidth while handling SOAP
Fig. 2. DDoS Attack Types
messages.
9) Slowloris: Using Slowloris, one web server may knock IV. DDOS COUNTERMEASURES
down another while leaving other web services and ports
There are several countermeasures/defense mechanisms
untouched. It maintains the utmost links as possible to target
available against DDoSattacks [14].
the webserver. As long as Slowloris is sending HTTP headers,
your request will never be fulfilled. Every false connection is A. Defense mechanisms-Intrusion based
kept open which causes legitimate users to deny additional An attacker seeking to obtain illegal access to the target
connections [13]. system or network is the driving force behind the majority of
10) NTP amplification: Attackers that utilize publicly DDoS assaults.
available NTP servers to flood the targeted host with UDP 1) Intrusion Prevention: Preventing an attack is the best
traffic are known as NTP amplification attackers. Anyone with mitigation policy against it. Some of the techniques included
access to a list of NTP servers may easily execute a DDoS are [15].
assault with significant bandwidth and volume. a) Prevention using Filters: Filtering strategies are used
11) Tear Drop attack: These attacks cause the Internet to protect a victim from known and unknown attackers. All
protocol data packets to be partitioned during network filtering techniques are used by Routers to guarantee that only
transmission, and each partition contains the original packet's valid traffic is granted access to a system. In this section, few
header, which helps reassemble the target host. When the filtering techniques were mentioned below.
TCP/IP stack becomes overburdened with Internet Protocol  Ingress filtering and Egress filtering[16].
pieces, reassembling becomes exceedingly complex and might  Route-based packet filtering [17].
fail quickly.  Hop Count filtering[18]
12) Land attack: It utilizes the “Land. c” code to transmit  History-based filtering[19]
altered syn packets with the victim's IP address in both the  Packet score[20]
 Path identifier[21]  In the ICMP traceback approach, each router
b) Honeypots: A Honeypot is a fictitious susceptible sends an ICMP trackback message to the
system that is used to be attacked, probed, exploited, and destination after sampling the forwarding
compromised. There is a honeypot technology that can be packets with a low probability. In this situation,
used to detect, identify and gather information on these threats no more ICMP messages will be sent to the
[22][23]. victim. To identify the attacker, a chain of
traceback messages was built.
c) Secure Overlay: Another prevention mechanism that
 Another technique for traceback is Link-testing
secures a group of networks is Secure Overlay. Layered
traceback which is used to figure out which
networks are created on top of Internet Protocol networks
packets carry the attacker’s traffic. The
which establish a communication to the protected network.
procedure begins with the router that is closest
The firewall allows only the trusted traffic to enter into the
to the target. The technique is repeated to test
protected network [24].
the upstream lines to determine which one
d) Load balancing: This approach balances loads of transports traffic.
different systems from overloading which helps to gain
optimal productivity and uptime [25]. B. Results Of Defense Mechanisms Related To Specific
Attack Type.
2) Intrusion Detection: These methods assist the victim to
detect the DDoS attack and preventing the system from 1) Suggested Defense Mechanisms and their results:
crashing. The Intrusion detection systems are mainly After presenting the defense mechanisms in the
classified into 2 types [26]: above section, here shows the [Link], a different set of
a) Network Intrusion Detection System (NIDS): A defense mechanisms related to specific DDoS attack
system that analyses the network traffic that is flowing into the types.
network. It is deployed at a critical network point or focus TABLE II: Suggested countermeasure‘s result for a Specific DDoS attack
where it supervises the inflow and outflow traffic from all the type
devices connected over a network. Recently the NIDS has
come with service in open stack cloud as Network Intrusion TYPE
ATTACK OF COUNTERMEASURE RESULT
Detection as a Service (NIDSasS) [27]. ATTACK
b) Host-Based Intrusion Detection System (HIDS): A Economic DDoS Mitigating the DDoS Using MTTSF, attack
DDoS attack attack bycalculating packets with high
system that keeps track of critical operating system files. It
the meantime.[31] overhead are identified
connects to the internet as well as the company’s intranet and and reduced.
works on all network devices. The HIDS is capable of DDoS For minimizing the Very high scalability,
detecting malicious traffic's abnormal network packets. It also DDoS attack effects of DDoS and little
detects malicious traffic coming from the host On cloud attacks, an Anomaly- computational
services based DDoS detection overhead
Subsets of IDS types exist as well. Signature detection, framework using TPA
Anomaly detection, and Specification-based detection are the is proposed [32].
Minor DDoS assaults
most prevalent versions. cannot be
 Signature Based: Monitors all network packets and immediately detected
compares them with the attack signature database or attributes Cyberattack DDoS In [33], A multi in this approach,
Attribute auction- attackers pay
of known malicious threats similar to antivirus software. based mechanism is according to a
 Anomaly Based: Identifies what is deemed typical for used to mitigate the different pricing
the network in terms of bandwidth, protocols, ports, and other DDoS attacks under structure, While
devices by comparing network traffic to a specified baseline. economic aspects. regular users pay
according to critical
 Specification-based detection: It detects the attacks value payment.
based on the manually indicated program cognitive For certain
requirements [28]. consumers, this
technique is only
3) Response to the Intruder Detection: When a DDoS available for premium
services.
attack is detected, it must be blocked and traced to track the SYN flood Protocol Attack detection based The attack detection is
identity of the attacker. Attackers frequently conceal their on statisticalTCP/IP quite accurate.
identities, making it difficult to defend them or identify and headers
prosecute them. There are few traceback techniques discussed
below[29].
 There is a technique called IP traceback that
allows each faked packet to be traced back to its
source [30].
ICMP flood Volumetric In [34], the High rate The high rate attack future work include real-time experimentation.
of ICMP
flood(HDDoS) can be
is detected
computing
by
the
 Existing protection techniques are insufficient to
detected and blocked frequency and authenticate legitimate users in a hostile environment,
by framing securing entropy values of the resulting in a denial of service attacks. Another
virtual rings around incoming packets.
preventing hosts Low-rate attacks can
limitation is packet loss in the case of high network
which will guard only be prevented by traffic, which allows malicious actors to infiltrate the
against the significant comparing the
degree of assaults by threshold value.
system. This high volume of communication results in
trading chosen traffic storage and computational overhead in attack
with Firecol . The low
rate of ICMP
prevention techniques.
flood(LDDoS) can be  Another ongoing research Problem is providing a
prevented by
employing a Halting
prevention technique against Zero-day attacks. DDoS
anomaly with a attackers are always developing new forms of attacks
weighted with increased power and complexity. As a result,
hoking(HAWK)
system. preventing a Zero-day attack is the most challenging
Smurf Volumetric In [35], the detection KLD Shewhart one, because this research involves an understanding of
attack of Smurf attack, are correctly detected all the attacker's behavior and skills which brings about
based on t h e introduced icmp
KLD metric which smurf attacks. novel types of DDoS attacks.
quantifies the
dissimilarity between
 With the detection techniques, the limitation of
two distributions of signature-based detection is that the system cannot
Smurf attacks.
Amplificatio Volumetric identify the unknown attacks. Anomaly detection can
In [36], the detection Attack detection is
nattacks of amplification quite accurate. help identify these unknown attacks. However,
attacks (DNS, NTP) is Because it inspects Anomaly detection has high false-positive rates that
carried by the just chosen packets
software-defined and minimizes the
result in additional consumption of resources and time.
network and machine load on the detecting Therefore the research direction would be to enhance
learning techniques. agent. the detection techniques concerning high accuracy,
UDP, TCP, Protocol In [37] to detect the The framework
ICMP attacks UDP, TCP, ICMP thread handles the
less consumption of resources, and computational time.
protocol attacks a incoming packets,
 When countering DDoS, it is necessary to maintain
multi-threaded IDS which are split and
framework is queued according to that the defense mechanisms utilize the least amount
proposed. It uses both the protocol. of victim’s resources as feasible. This is an
signature and The accuracy
anomaly-based IDS. achieved by the UDP,
extremely essential research topic because the
ICMP, and SYN flood effective defense mechanisms guarantee the least
is 98.64,99.33%, and amount of downtime and revenue loss from the
99.37% respectively
HTTP Application- In [38] The HTTP On a public dataset,
victim’s side.
DDoS level DDoS assault is five classifiers were  The detection algorithms analyze the distortion or
identified using the employed for
Random Forest detection which
deviation in the performance metrics. They detect
Ensemble learning achieved high the attack based on statistical modeling. Further
method and accuracy. study can enhance the detection of DDoS attacks
information-theoretic
entropy. using learning algorithms.
Despite the amount of study done, there are still issues to be
solved in this field. To defend against DDoS assaults,
V. RESEARCH OUTCOME further research is needed to discover effective detection
This Review paper described the comprehensive survey and prevention mechanisms for any form of DDoS attacks.
of DDoS attacks and their defense mechanism in Cloud
VI. CONCLUSION AND FUTURE WORK
computing. This paper presented the academic research of
DDoS attacks against cloud incursions and the various As DDoS attacks are on the ascent in every single arising
innovation, we can expect a ton of safety efforts and
mitigation techniques published mostly between 2010 and comparing weaknesses in the future. This paper as the
2020. The key findings from the survey include: beginning, gives a concise overview of Cloud computing,
Security issues of the cloud, insights into DDoS attacks, and
 Most of the mitigation techniques described are
finally its defense mechanisms. According to this review, it is
implemented using simulation tools. It is suggested that the DDoS attack that poses the greatest danger to internet
infrastructure and the advancement of information technology. Jul. 20, 2021).
It is also concealed from the study that there is a much need [14] “DoS Attacks and Countermeasures - PCcare.”
for pattern analysis and classification to distinguish legitimate [Link] pages/dos-
traffic from malicious traffic. attacks-and-countermeasures (accessed Jun.27, 2021).
The future work is to identify the attacker source and [15] T. Mahjabin, Y. Xiao, G. Sun, and W. Jiang, “A survey of
to create a defense mechanism to detect and mitigate the distributed denial-of-service attack, prevention, and mitigation
DDoS attacks. Hence it is necessary to create a secure cloud techniques,” Spec. Issue Artic. Int. J. Distrib. Sens. Networks,
vol. 13, no. 12, p. 2017, 2017, doi:
infrastructure that can survive future attacks while reducing 10.1177/1550147717741463.
the vulnerabilities that have already been identified.
[16] S. Wadhwa, P. Saini, and C. Ramakrishna, “Prevention of
REFERENCES DDoS & EDOS using Hybrid Filtering Technique in a Cloud
Environment,” Accessed: Jul. 28, 2021. [Online]. Available:
[Link]
[1] Senyo, Prince Kwame Addae, Erasmus Boateng, Richard
“Cloud computing research: A review of research themes, [17] K. Park and H. Lee, “On the Effectiveness of Route- Based
frameworks, methods and future research directions,” Packet Filtering for Distributed DoS Attack Prevention in
International Journal of Information [Link] Power-Law Internets *,” 2001.
38, Issue 1, February 2018, Pages 128-139 139
[18] S. Sultana, S. Nasrin, F. K. Lipi, M. A. Hossain, Z. Sultana,
[2] U. Gurav and R. Shaikh, “Virtualization: A key feature of and F. Jannat, “Detecting and Preventing IPSpoofing and
cloud computing,” ICWET 2010 - Int. Conf. Work. Emerg. Local Area Network Denial (LAND) Attack for Cloud
Trends Technol. 2010, Conf. Proc., no. July 2020, pp. 227– Computing with the Modification of Hop Count Filtering
229, 2010, doi: 10.1145/1741906.1741957. (HCF) Mechanism,” 5th Int. Conf. Comput. Commun.
Chem. Mater. Electron. Eng.IC4ME2 2019, Jul. 2
[3] P. R. K. Reddy and S. Bouzefrane, “Analysis and detection
of DoS attacks in cloud computing by using QSE algorithm,” [19] T. V. Phan and M. Park, “Efficient distributed denial- of-
Proc. - 16th IEEE Int. Conf. High Perform. Comput. service attack defense in sdn-based cloud,” IEEE Access, vol.
Commun. HPCC 2014, 11th IEEE Int. Conf. Embed. Softw. 7, pp. 18701–18714, 2019, doi:
Syst. ICESS 2014 6th Int. Symp. Cybersp. Saf. Secur., pp. 10.1109/ACCESS.2019.2896783.
1089–1096, 2014, doi:10.1109/HPCC.2014.183.
[20] A. Gaurav, B. B. Gupta, C.-H. Hsu, D. Perakovic, and F. J.
[4] G. S. Kushwah and V. Ranga, “Voting extreme learning GARCIA PENALVO, “Filtering of Distributed Denial of
machine based distributed denial of service attack detection Services (DDoS) Attacks in Cloud Computing
in cloud computing,” J. Inf. Secur. Appl., vol. 53, p. 102532, Environment,” 2021 IEEE Int. Conf. Commun. Work. (ICC
Aug. 2020, doi:10.1016/[Link].2020.102532. Work., pp. 1–6, Jun. 2021, doi:
10.1109/ICCWORKSHOPS50388.2021.9473886.
[5] V. K. Prasad, M. D. Bhavsar, and N. Patel, “Chronicles of
Assaults at Cloud Computing and Its Influence at an IaaS,” [21] P. Sudharsanarao and S. Durga Prasad, “Detecting And
SSRN Electron. J., pp. 614–620,2018, doi: Preventing Of Dos Attacks By Dynamic Path Identifier
10.2139/ssrn.3170190. Networks,” Int. J. Comput. Sci. Trends Technol., vol. 7,
2013, [Online]. Available: [Link].
[6] C. Stergiou, K. E. Psannis, B. B. Gupta, and Y. Ishibashi,
“Security, privacy & efficiency of sustainable Cloud [22] M. Dagar and R. Popli, “Honeypots: Virtual Network
Computing for Big Data & IoT,” Sustain. Comput. Informatics Intrusion Monitoring System,” 2018, Accessed: Jul. 07,2021.
Syst., vol. 19, no. May, pp. 174–184, [Online]. Available :[Link].
2018, doi:10.1016/[Link].2018.06.003.
[23] P. S. Negi, A. Garg, and R. Lal, “Intrusion detection and
[7] B. Mulyawan, R. Kosala, B. Ranti, and S. [Link], “Cloud prevention using honeypot network for cloud security,”
computing model in higher education,” IOP Conf. Ser. Mater. Proc. Conflu. 2020 - 10th Int. Conf. Cloud Comput. Data
Sci. Eng., vol. 852, no. 1, 2020, doi: 10.1088/1757- Sci. Eng., pp. 129–132, 2020, doi:
899X/852/1/012178. 10.1109/Confluence47617.2020.9057961.
[8] P. Mell, T. Grance, and T. Grance, “The NIST Definition of [24] S. S. Chowriwar, M. S. Mool, P. P. Sabale, S. S. Parpelli, M.
Cloud Computing Recommendations of the National Institute of Nilesh, and S. #5, “Mitigating Denial-of- Service Attacks
Standards and Technology.” Using Secure Service Overlay Model,” Int. J. Eng. Trends
Technol., vol. 8, no. 9, 2014, Accessed: Jul. 28, 2021.
[9] M. A. Khan, “A survey of security issues for cloud computing,”
[Online]. Available: [Link]
J. Netw. Comput. Appl., vol. 71, pp. 11– 29, 2016, doi:
10.1016/[Link].2016.05.010. [25] “DNS, Load Balancing and DDOS attacks - Load
Balancers.” [Link]
[10] M. A. Bamiah and S. N. Brohi, “Seven Deadly Threats and
balancing-and-ddos-attacks/ (accessed Jul. 28, 2021).
Vulnerabilities in Cloud Computing - [Link]- Vol-No-9-
Issue-No-1,” no. 9, pp. 87–90, 2011. [26] “What is an Intrusion Detection System (IDS) and How
Does it Work?”
[11] S. M. Specht and R. B. Lee, “Distributed Denial of Service:
[Link] on-
Taxonomies of Attacks, Tools and Countermeasures,” Int.
detection-system (accessed Jul. 04, 2021).
Work. Secur. Parallel Distrib. Syst., no. 9, pp. 543–550, 2004.
[27] C. Xu, R. Zhang, M. Xie, and L. Yang, “Network Intrusion
[12] “(1) New
Detection System as a Service in OpenStack Cloud,” in 2020
Message!” [Link]
International Conference on Computing, Networking and
ddos/ (accessed Jun. 30, 2021).
Communications, ICNC 2020, Feb. 2020, pp. 450–455, doi:
[13] “DDoS Attack Types & Mitigation Methods | Imperva.” 10.1109/ICNC47757.2020.9049480.
[Link] attacks/ (accessed
[28] P. Uppuluri and R. Sekar, “Experiences with Specification-
Identify applicable sponsor/s here. If no sponsors, delete this text box
(sponsors).
based Intrusion Detection.” [35] B. Bouyeddou, F. Harrou, Y. Sun, and B. Kadri, “Detection
of smurf flooding attacks using Kullback- Leibler-based
[29] A. P. S, P. Scholar, and A. Professor “A Survey On Ip
scheme,” 2018 4th Int. Conf. Comput. Technol. Appl. ICCTA
Traceback Techniques,”. Int. Res. J. Eng. Technol., 2017,
2018, pp. 11–15, Jun. 2018, doi:
Accessed: Jul. 07, 2021. [Online]. Available: [Link].
10.1109/CATA.2018.8398647.
[30] V. Murugesan, M. S. Selvaraj, and M.-H. Yang “HPSIPT: A
high-precision single-packet IP traceback scheme,” Comput.
[36] C. C. Chen, Y. R. Chen, W. C. Lu, S. C. Tsai and M.C.
Yang, “Detecting amplification attacks with Software
Networks, vol. 143, pp. 275–288, 2018, doi: 10.1016/
Defined Networking,” 2017 IEEE Conf. Dependable Secur.
[Link].2018.07.013
Comput., pp. 195–201, 2017, doi:
[31] P. Daffu and A. Kaur, “Mitigation of DDoS attacks in cloud 10.1109/DESEC.2017.8073807.
computing,” 2016 5th Int. Conf. Wirel. Networks Embed.
[37] R. Patil, H. Dudeja, S. Gawade, and C. Modi, “Protocol
Syst. WECON 2016, 2017, doi: 10.1109/
Specific Multi-Threaded Network Intrusion Detection
WECON.2016.7993478.
System (PM-NIDS) for DoS/DDoS Attack Detection in
[32] S. Mahdavi Hezavehi and R. Rahmani, “An anomaly- based Cloud,” 2018 9th Int. Conf. Comput. Commun. Netw.
framework for mitigating effects of DDoS attacks using a Technol. ICCCNT 2018, Oct. 2018, doi: 10.1109/
third party auditor in cloud computing environments,” ICCCNT.2018.8494130.
Cluster Comput., vol. 23, no. 4, pp. 2609–2627, 2020, doi:
[38] M. Idhammad, K. Afdel, and M. Belouch, “Detection System
10.1007/ s10586-019-03031-y.
of HTTP DDoS Attacks in a Cloud Environment Based on
[33] A. Dahiya and B. B. Gupta, “Multi attribute auction based Information Theoretic Entropy and Random Forest,” Secur.
incentivized solution against DDoS attacks,” Comput. Commun. Networks, vol. 2018, doi: 10.1155/2018/1263123
Secur., vol. 92, p. 101763, May 2020, doi: 10.1016/
[Link].2020.101763.
[34] M. A. V. Kumar and R. Udayakumar, “Identifying and
Blocking High and Low Rate DDOS ICMP Flooding,”
Indian J. Sci. Technol., vol. 8, no. 32, 2015, doi:
10.17485/ijst/2015/v8i32/84409.

View publication stats

Common questions

Powered by AI

Countermeasures against DDoS attacks in cloud environments include intrusion prevention techniques such as filtering mechanisms and honeypots, which are designed to prevent known and unknown attacks by analyzing traffic and detecting malicious activity . Secure overlay networks and load balancing are also used to enhance the resilience of cloud services by distributing traffic loads and filtering out DDoS attack traffic before it reaches the target . These techniques vary in effectiveness depending on the attack scale and type; while effective for many known types of DDoS attacks, new and sophisticated attack methods, like zero-day vulnerabilities, challenge existing defenses, indicating a need for continuous innovation in security measures .

Cloud computing achieves resource pooling by allowing multiple users to share computing resources through virtualization, which enables a single physical instance of a resource to be used by many customers and organizations . This pooling is facilitated by technologies that allocate shared resources dynamically based on demand, enhancing efficiency and flexibility. The impact on cost is significant; pooling reduces costs for users because it allows cloud service providers to maximize resource utilization and economies of scale, which consequently lowers prices for customers who pay only for what they use, instead of maintaining expensive in-house infrastructure .

Distributed Denial of Service (DDoS) attacks are a type of cyber attack where multiple infected systems are used to flood a target system with requests, overwhelming it and rendering it unavailable to legitimate users . They are a significant threat to cloud computing security due to their ability to disrupt service availability, which is a critical attribute of cloud services. DDoS attacks primarily target the infrastructure level of cloud platforms, which can affect all layers of service provided on the cloud, including PaaS and SaaS, thereby compromising not just availability but also potentially affecting security and privacy across the cloud environment .

Virtualization plays a crucial role in cloud computing by enabling the creation of virtual instances of resources such as servers, storage, and networks from a single physical hardware resource, allowing multiple users to access and utilize these resources efficiently . Its implications for scalability are profound, as virtualization allows cloud providers to dynamically allocate and manage resources according to demand, facilitating rapid elasticity, one of the defining characteristics of cloud computing . However, this also introduces security challenges, such as vulnerabilities in the hypervisor and potential risks associated with virtual machine migration, necessitating robust security measures to protect against breaches that could affect multiple virtual environments simultaneously .

The primary service models offered in cloud computing are Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS). IaaS provides infrastructure computing facilities like processing power, storage, and networks, allowing customers to manage their computing resources more flexibly . PaaS offers a runtime environment for developing and deploying software, reducing the complexity of managing underlying hardware and software stacks . SaaS delivers software applications over the internet, allowing users to access the provider's apps without handling the infrastructure, which simplifies the software use and management for end-users . Each model caters to different needs—IaaS targets those needing extensive control over their infrastructure, PaaS supports developers focusing on application development, and SaaS appeals to end-users seeking functionality without IT management concerns.

Scalability in cloud computing refers to the ability to increase resource capacity to meet long-term, growth-driven demands, allowing businesses to expand services by adding resources like storage or processing power as the need grows . Elasticity, on the other hand, refers to the ability of the cloud to dynamically allocate resources to cope with short-term, variable workloads, enabling rapid scaling up or down without manual intervention . Both concepts are critical for service efficiency; scalability ensures that services can grow with business needs, maintaining performance levels as usage increases, while elasticity ensures resource allocation is optimal and cost-effective, adjusting to user demands in real-time . This ensures efficient utilization of resources, maintaining a balance between performance and cost.

SaaS security threats include application security vulnerabilities, data security issues, and challenges related to multi-tenancy, where data from different users resides on the same physical hardware . PaaS faces security challenges such as third-party relationships, the integrity of the development lifecycle, and underlying infrastructure security that could affect platforms . For IaaS, key threats involve Virtualization threats, such as VM Hypervisor vulnerabilities, risks in VM networks, rollback, and VM migration complexities . These threats highlight the layers of security necessary to protect cloud services at every level, from application to infrastructure, ensuring data privacy, integrity, and availability across the cloud stack.

The NIST defines five essential attributes of cloud computing that ensure efficient service delivery and resource management: On-demand self-service, Broad network access, Resource pooling, Rapid elasticity, and Measured service . On-demand self-service allows users to provision resources automatically without interaction with service providers, increasing convenience and efficiency. Broad network access ensures services are available over the network and accessed through standard mechanisms that promote use by heterogeneous client platforms. Resource pooling is achieved through multi-tenancy models, dynamically allocating resources based on demand. Rapid elasticity allows resources to be scaled rapidly outward and inward based on demand, which is crucial for handling varying workloads effectively. Finally, measured service involves monitoring resources and providing transparency for both provider and consumer on the services utilized, which aids in efficient resource management and cost control .

The public cloud deployment model makes services available to the general public, either free or pay-per-use, ideal for organizations seeking cost-effective, scalable resources without concern over data privacy . The private cloud is exclusive to one organization, providing more control over data security and compliance, suitable for businesses with critical data privacy needs . Hybrid clouds combine public and private clouds, allowing data and applications to be shared between them, offering flexibility and optimizing workloads by leveraging benefits of both cloud types . Community clouds are shared by several organizations with similar requirements and concerns, like regulatory compliance, enabling cost-sharing while maintaining some privacy controls . Each model addresses different needs based on organizational priorities such as cost, control, privacy, and regulatory compliance .

The Slowloris attack is significant in evaluating cloud security measures as it maintains open connections with minimal bandwidth, making network usage hard to detect and requiring advanced security strategies to handle such stealthy, low-bandwidth attacks . NTP amplification uses publicly available NTP servers to magnify attack traffic directed towards a target, exploiting weaknesses in the protocol to launch high-volume attacks with minimal effort from the attacker . These attack types highlight the need for robust, multi-layered security measures capable of detecting and mitigating varied and evolving threats, emphasizing the importance of continuous monitoring and adaptation of security systems in cloud environments .

You might also like