首页 | 本学科首页   官方微博 | 高级检索  
     

基于虚拟散列安全访问路径VHSAP的云计算路由平台防御DDoS攻击方法
引用本文:吴志军,崔 奕,岳 猛.基于虚拟散列安全访问路径VHSAP的云计算路由平台防御DDoS攻击方法[J].通信学报,2015,36(1):30-37.
作者姓名:吴志军  崔 奕  岳 猛
作者单位:中国民航大学 天津市智能信号处理重点实验室,天津 300300
基金项目:国家自然科学基金资助项目(61170328,U1333116);天津市应用基础与前沿技术研究计划基金资助项目(12JCZDJC20900);2013年民航科技引导基金资助项目(MHRD20130217);中国民航大学科研平台建设基金资助项目;中央高校基本科研业务费基金资助项目(3122013P007, 3122013D007, 3122013D003)
摘    要:防御分布式拒绝服务DDoS(distributed denial of service)攻击是云计算平台安全保护中的一个关键问题。在研究大规模网络防御DDoS攻击的安全覆盖服务SOS(security overlay service)方法的基础上,揭示了SOS在节点被攻击时的退出机制存在的安全漏洞,根据云计算路由策略改进了一致性散列算法Chord,提出了适用于云计算路由平台三层架构的虚拟散列安全访问路径VHSAP(virtualization hash security access path),在安全访问路径中引入了心跳机制,利用虚拟机技术实现弹性的虚拟节点,完成在云平台中被攻击节点之间的无缝切换,保证用户对云计算平台的安全访问。针对VHSAP防御DDoS的性能进行了仿真实验,重点研究了在散列安全访问路径HSAP中被攻击节点数和切换时延等参数,并将实验结果与SOS方法进行了比较。实验结果表明在DDoS攻击下,VHSAP具有较高的数据通过率,可以提高云计算平台的安全性。

关 键 词:云计算  路由平台  DDoS  一致性散列  虚拟化  无缝切换
收稿时间:6/4/2013 12:00:00 AM

VHSAP-based approach of defending against DDoS attacks for cloud computing routing platforms
UZhi-jun W,UIYi C,UEMeng Y.VHSAP-based approach of defending against DDoS attacks for cloud computing routing platforms[J].Journal on Communications,2015,36(1):30-37.
Authors:UZhi-jun W  UIYi C  UEMeng Y
Affiliation:Tianjin Key Laboratory for Advanced Signal Processing,Civil Aviation University of China,Tianjin 300300,China
Abstract:Based on the analysis of security overlay service (SOS) approach of defending against DDoS attacks in large scale network,the vulnerability in the exit mechanism of being attacked nodes in SOS approach is explored.The vulnerability is solved by improving the Chord algorithm according to the routing strategy in cloud computing.Hence,the virtualization hash security access path (VHSAP) in three-layer structure is proposed to protect the cloud computing platform.In VHSAP,the heartbeat mechanism is applied to realize virtual nodes by using the virtual technology.Therefore,the virtual nodes have the ability of resilience,which can complete the seamless switching between being attacked nodes in cloud computing platform,and guarantee the legitimate user's authority of accessing to the resource in cloud computing platform.Experiments of VHSAP defending against DDoS attacks are carried out in simulation network environment.The parameters,such as the number of being attacked nodes in hash secure access path (HSAP),and the switching time and the handoff delay between nodes,are focused in experiments.The result shows that VHSAP achieves a higher data pass rate than that of SOS approach,and enhances the security of cloud computing platform.
Keywords:cloud computing  routing platforms  DDoS  consistent hashing algorithm  virtualization  seamless switch
点击此处可从《通信学报》浏览原始摘要信息
点击此处可从《通信学报》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号