Mitigation of DDoS Attacks using Entropy and Proof-of-Work Based Puzzle in OpenStack Cloud
Ritesh Patil, D. G. Narayan · 2023
Cloud computing is a model that allows users to obtain computer resources through the Internet without the need for local infrastructure or physical hardware. With the increased reliance on cloud computing, security concerns have arisen, making it crucial for businesses to ensure that their operation is protected and secured in the cloud. One of the important cyber attack on cloud is Distributed Denial of Service (DDoS). Many AI based techniques are used to detect DDoS attacks. In recent research, there has been a growing focus on developing detection mechanisms for DDoS attacks using unsupervised learning and puzzle-based techniques. While some studies have successfully mitigated these attacks using proof of work, puzzle-based approaches can introduce implementation challenges. To address this, our work introduces a two-step approach for mitigating DDoS attacks using combination of entropy and puzzle based techniques. Initially, an entropy based detection is employed to detect the suspicious host machines pinpointing potential targets for attacks. Subsequently, a puzzle-based technique is utilized to identify attacker hosts. To establish a connection with the server, clients are required to solve a cryptographic puzzle, effectively preventing unauthenticated clients from launching attacks. This adoption of client puzzles also provides protection against unknown attacks that may exploit vulnerabilities. Importantly, our proposed technique eliminates the need for training data, making it a more efficient and adaptable solution to combat DDoS attacks. The proposed technique is evaluated in OpenStack-based cloud testbed. Results reveal that the entropy based approach combined with POW puzzle performs better than ML based approach.