Multi Layered Defense Architecture for DDoS Protection in Private Cloud Environments
Shashwat Singh, Anubha Sharma, Shani Soni, Ayushi Prakash · 2024
Private cloud solutions have increasingly been adopted because of the demand from organizations for enhanced data security, control over regulatory compliance, and IT infrastructure has been rising. Although public cloud services offer built-in security solutions, private clouds must possess a custom built architectures to address critical challenges, including Distributed Denial of Service (DDoS) attacks, among others.Services are often deployed behind private cloud environments without the benefits of prebuilt SaaS based DDoS protection. In this exposition, we present an architecture for multilayer protection against DDoS attacks in private cloud environments, which includes the following key components: Global Load Balancer, Traffic Scrubbing Center, Signature based IDPS, and Command and Control Center. Further, we also present a custom Command and Control Center, which utilizes CNNs for runtime handling of network traffic flow, based on real-time monitoring and activity patterns, to mitigate the menace of DDoS. Experimental results show that the architecture is efficient in filtering volumetric and application layer DDoS attacks, ensuring a malicious packet drop rate greater than 95%, while maintaining latency below 150 ms.