Detecting fraudulent use of cloud resources

Detecting fraudulent use of cloud resources
复制标题

DOI:
10.1145/2046660.2046676
复制
发表时间:
2011-10
期刊:
--
影响因子:
--
通讯作者:
Joseph Idziorek;Mark Tannian;D. Jacobson
Joseph Idziorek;Mark Tannian;D. Jacobson
中科院分区:
其他
文献类型:
--
作者:
Joseph Idziorek;Mark Tannian;D. Jacobson

文献摘要

被引文献

相似文献

公共云模型的初始威胁建模和安全研究主要集中在云中传输、处理和存储的数据的机密性和完整性。很少有人关注外部威胁来源,这些威胁来源有能力影响公共云中托管的服务的财务可行性,从而影响其长期可用性。与应用层DDoS攻击类似,欺诈性资源消耗(FRC)攻击是一种在较长时间内进行的更微妙的攻击。攻击者的目标是利用效用定价模型,该模型通过欺诈性地消费Web内容来管理云模型中的资源使用,目的是剥夺受害者在云中托管可公开访问的Web内容的长期经济可用性。在本文中,我们彻底描述了FRC攻击,并讨论了为什么目前的应用层DDoS检测方案不适用于更微妙的攻击。我们提出了三个检测指标,共同形成的标准,从正常的Web活动识别FRC攻击。基于三种可能的攻击场景的实验结果表明,攻击者不知道的Web日志有一个困难的时间模仿正常的Web活动的自相似和一致的请求语义。
Initial threat modeling and security research on the public cloud model has primarily focused on the confidentiality and integrity of data transferred, processed, and stored in the cloud. Little attention has been paid to the external threat sources that have the capability to affect the financial viability, hence the long-term availability, of services hosted in the public cloud. Similar to an application-layer DDoS attack, a Fraudulent Resource Consumption (FRC) attack is a much more subtle attack carried out over a longer duration of time. The objective of the attacker is to exploit the utility pricing model which governs the resource usage in the cloud model by fraudulently consuming web content with the purpose of depriving the victim of their long-term economic availability of hosting publicly accessible web content in the cloud. In this paper, we thoroughly describe the FRC attack and discuss why current application-layer DDoS detection schemes are not applicable to a more subtle attack. We propose three detection metrics that together form the criteria for identifying a FRC attack from that of normal web activity. Experimental results based on three plausible attack scenarios show that an attacker without knowledge of the web log has a difficult time mimicking the self-similar and consistent request semantics of normal web activity.