A Risk and Vulnerability Assessment in Cloud for DDOS Attacks

Manas Tripathi · SSRN Electronic Journal · 2016

An attacker, can swarm the cloud service provider (CSP), by a large number of request, by compromising various vulnerable systems (zombies). These Distributed Denial of Service (DDoS) attacks can have serious business impact to users of CSP. There are many solutions to mitigate this challenge but most of the methods allow the attack traffic to arrive at CSP and then only take actions. In this paper we propose a Cyber Risk Assessment (CRA) framework for cloud, based on Dijkstra's and Yen’s algorithm. Our CRA for cloud takes the network topology, security of technology at each node and the cost of compromise as the input. It outputs the most vulnerable paths for a CSP in advance without waiting for the traffic to arrive at CSP. In this paper we assume that the cost of compromise of a node depends on the level of security technology deployed at each node of the network. We then assess the expected loss associated with each of these vulnerable paths by multiplying the probabilities of attack for these paths with the potential loss.

Read the paper · More papers on PaperTik