RESCUE:Resolving security Issues in Virtual Networks *
B. S. Liya · 2014
Cloud security is one of the most important issues that has attracted a lot of research and development effort in past few years. Particularly, attackers can eplore vulnerabilities of a cloud system and compromise virtual machines to deploy further largescale Distributed Denial-of-service (DDoS). DDoS attacks usually involve early stage actions such as multistep exploitation, low frequency vulnerability scanning, and compromising identified vulnerable virtual machine as zombies, and finally DDoS attacks through the compromised zombies. Within the cloud system, especialy the infrastructure-as-a-service (IaaS) clouds, the detection of zombie exploration attacks is etreamly difficult. This is because cloud users may install vulnerable applications on their virtual machines. To prevent vulnerable virtual machines from being compromised in the cloud, we propose amulti-phase distributed vulnerability detection, measurement, and counter measureselection mechanism called RESCUE, which is built on attack graph based analytical models and reconfigurable virtual network based counter measures. The proposed framework leverages OpenFlow network programming APIs to built a monitor and control plane over distributed programmable virtual switches to significantly improve attack detection and mitigate attack consequences. The system and security evaluations demonstrate the efficiency and effectiveness of the proposed solution.