TY - JOUR
T1 - Frequency-Minimal Utility-Maximal Moving Target Defense against DDoS in SDN-Based Systems
AU - Debroy, Saptarshi
AU - Calyam, Prasad
AU - Nguyen, Minh
AU - Neupane, Roshan Lal
AU - Mukherjee, Bidyut
AU - Eeralla, Ajay Kumar
AU - Salah, Khaled
N1 - Funding Information:
Manuscript received June 14, 2019; revised November 8, 2019, January 23, 2020, and February 9, 2020; accepted February 10, 2020. Date of publication March 4, 2020; date of current version June 10, 2020. This material is based upon work supported by the National Science Foundation under Award Number: CNS-1359125 and Thomson Reuters. The associate editor coordinating the review of this article and approving it for publication was Q. Li. (Corresponding author: Prasad Calyam.) The authors are with the Department of Computer Science, City University of New York, New York, NY 10017 USA, also with the Department of Electrical Engineering and Computer Science, University of Missouri–Columbia, Columbia, MO 65211 USA, and also with the Department of Computer Engineering, Khalifa University, Abu Dhabi, UAE (e-mail: [email protected]; [email protected]; [email protected]; [email protected]; bm346 @mail.missouri.edu; [email protected]; [email protected]). Digital Object Identifier 10.1109/TNSM.2020.2978425
Publisher Copyright:
© 2019 IEEE.
PY - 2020/6
Y1 - 2020/6
N2 - With the increase of DDoS attacks, resource adaptation schemes need to be effective to protect critical cloud-hosted applications. Specifically, they need to be adaptable to attack behavior, and be dynamic in terms of resource utilization. In this paper, we propose an intelligent strategy for proactive and reactive application migration by leveraging the concept of 'moving target defense' (MTD). The novelty of our approach lies in: (a) stochastic proactive migration frequency minimization across heterogeneous cloud resources to optimize migration management overheads, (b) market-driven migration location selection during proactive migration to optimize resource utilization, cloud service providers (CSPs) cost and user quality of experience, and (c) fast converging cost-minimizing reactive migration coupled with a 'false reality' pretense to reduce the future attack success probability. We evaluate the effectiveness of our proposed MTD-based defense strategy using a Software-defined Networking (SDN) enabled GENI Cloud testbed for a 'Just-in-time news articles and video feeds' application. Our frequency minimization results show more than 40% reduction in DDoS attack success rate in the best cases when compared to the traditional periodic migration schemes on homogeneous cloud resources. The results also show that our market-driven migration location selection strategy decreases CSP cost and increases resource utilization by 30%.
AB - With the increase of DDoS attacks, resource adaptation schemes need to be effective to protect critical cloud-hosted applications. Specifically, they need to be adaptable to attack behavior, and be dynamic in terms of resource utilization. In this paper, we propose an intelligent strategy for proactive and reactive application migration by leveraging the concept of 'moving target defense' (MTD). The novelty of our approach lies in: (a) stochastic proactive migration frequency minimization across heterogeneous cloud resources to optimize migration management overheads, (b) market-driven migration location selection during proactive migration to optimize resource utilization, cloud service providers (CSPs) cost and user quality of experience, and (c) fast converging cost-minimizing reactive migration coupled with a 'false reality' pretense to reduce the future attack success probability. We evaluate the effectiveness of our proposed MTD-based defense strategy using a Software-defined Networking (SDN) enabled GENI Cloud testbed for a 'Just-in-time news articles and video feeds' application. Our frequency minimization results show more than 40% reduction in DDoS attack success rate in the best cases when compared to the traditional periodic migration schemes on homogeneous cloud resources. The results also show that our market-driven migration location selection strategy decreases CSP cost and increases resource utilization by 30%.
KW - Cloud security
KW - DDoS attack
KW - moving target defense
KW - software-defined networking
UR - http://www.scopus.com/inward/record.url?scp=85081337854&partnerID=8YFLogxK
U2 - 10.1109/TNSM.2020.2978425
DO - 10.1109/TNSM.2020.2978425
M3 - Article
AN - SCOPUS:85081337854
SN - 1932-4537
VL - 17
SP - 890
EP - 903
JO - IEEE Transactions on Network and Service Management
JF - IEEE Transactions on Network and Service Management
IS - 2
M1 - 9023955
ER -