Journal on Communications ›› 2015, Vol. 36 ›› Issue (1): 30-37.doi: 10.11959/j.issn.1000-436x.2015004

• Academic paper • Previous Articles     Next Articles

VHSAP-based approach of defending against DDoS attacks for cloud computing routing platforms

UZhi-jun W,UIYi C,UEMeng Y   

  1. Tianjin Key Laboratory for Advanced Signal Processing,Civil Aviation University of China,Tianjin 300300,China
  • Online:2015-01-25 Published:2017-06-21
  • Supported by:
    The National Natural Science Foundation of China;The National Natural Science Foundation of China;The Key Project of Tianjin Natural Science Foundation;Civil Aviation Science and Technology Innovation Fund;Research Laboratory Construction Funds of Civil Aviation University of China;Fundamental Research Funds for the Central Universities;Fundamental Research Funds for the Central Universities;Fundamental Research Funds for the Central Universities

Abstract:

Based on the analysis of security overlay service (SOS) approach of defending against DDoS attacks in large scale network,the vulnerability in the exit mechanism of being attacked nodes in SOS approach is explored.The vulnerability is solved by improving the Chord algorithm according to the routing strategy in cloud computing.Hence,the virtualization hash security access path (VHSAP) in three-layer structure is proposed to protect the cloud computing platform.In VHSAP,the heartbeat mechanism is applied to realize virtual nodes by using the virtual technology.Therefore,the virtual nodes have the ability of resilience,which can complete the seamless switching between being attacked nodes in cloud computing platform,and guarantee the legitimate user's authority of accessing to the resource in cloud computing platform.Experiments of VHSAP defending against DDoS attacks are carried out in simulation network environment.The parameters,such as the number of being attacked nodes in hash secure access path (HSAP),and the switching time and the handoff delay between nodes,are focused in experiments.The result shows that VHSAP achieves a higher data pass rate than that of SOS approach,and enhances the security of cloud computing platform.

Key words: cloud computing, routing platforms, DDoS, consistent hashing algorithm, virtualization; seamless switch

No Suggested Reading articles found!