|国家预印本平台
首页|基于虚拟机迁移的DoS攻击防御方法

基于虚拟机迁移的DoS攻击防御方法

中文摘要英文摘要

利用云计算资源共享的特性,攻击者可以通过不停消耗带宽资源,使得同一物理主机上的其他用户无法接受正常服务,造成拒绝服务(denial of service,DoS)攻击。这种攻击区别于传统网络体系中的DoS攻击,因此难以应用传统防御方法解决。针对这一问题,提出一种基于虚拟机迁移的DoS攻击防御方法,通过选择迁移目标、设计触发机制和选择迁移目的地,形成迅速减轻DoS攻击影响的虚拟机迁移策略。实验结果表明,针对攻击者的不同攻击方式,该方法均可有效地快速防御DoS攻击,保证云服务的正常运行。相比其他策略,所提方法在迁移开销上略有增加,但防御效果明显,可行性更高。

By utilizing the characteristics of resource sharing in cloud computing, attackers can launch DoS attack by constantly consuming bandwidth resources so that other users on the same physical host can not receive normal services. This attack mode is different from the DoS attack in traditional network system, so it is difficult to apply traditional defense method to solve it. To solve this problem, this paper proposes a DoS attack defense method based on virtual machine migration. By selecting the migration target, designing the triggering mechanism and selecting the migration destination, a virtual machine migration strategy is proposed to mitigate the impact of DoS attacks. The experimental results demonstrate that this method can effectively defend DoS attack and ensure the normal operation of cloud service whatever different attack methods that attackers may use. Compared with other methods, the proposed strategy leads a litter more migration cost, however, its better in defense effect and feasibility.

刘文彦、程国振、杨超、张淼、霍树民、季新生

10.12074/201804.02389V1

电子对抗通信计算技术、计算机技术

云计算oS攻击虚拟机迁移

刘文彦,程国振,杨超,张淼,霍树民,季新生.基于虚拟机迁移的DoS攻击防御方法[EB/OL].(2018-04-24)[2025-08-16].https://chinaxiv.org/abs/201804.02389.点此复制

评论