Securing Cloud-Based Systems: DDoS Attack Mitigation using Hypervisor-Intrusion Detection Approach

Surendra Kumar, Pawan Kumar, Jaydip Kumar, Virendra Singh, Arun Singh Yadav · Procedia Computer Science · 2025

The principle of virtualization and cloud-based technology has facilitated various industries in establishing expansive cloud environments. The Cloud is vulnerable to emerging threats and breaches due to the nature of its networks. Creating an intrusion system that addresses security concerns in cloud networks is crucial. This paper examines specific security weaknesses associated with significant threats, such as Distributed Denial-of-Service (DDoS) assaults, which jeopardize both data security and service availability in Cloud systems. To address these concerns, a Hypervisor Controller-based detection system has been developed for the identification of DDoS attacks. The Hypervisor Controller employs Fuzzy Time Series Analysis and Expectation Maximization methods in a dual-phase process. In the preliminary phase, resource requests are categorized according to their compliance with the Service Level Agreement (SLA). Requests that contravene the Service Level Agreement (SLA) are promptly identified as potential malware and denied from system access, thereby preserving the system’s security and stability. In the second step, non-violation requests undergo rigorous examination utilizing a Fuzzy Time Series model, simulated by the Expectation Maximization method. This method proficiently manages large datasets, significantly enhancing detection accuracy. The proposed Hypervisor Controller has demonstrated effectiveness, robustness, and immediacy in detecting DDoS attacks across federated systems and cloud environments, as evidenced by experimental and performance evaluations. This study aims to enhance the security of Cloud-integrated systems by formulating comprehensive and effective solutions to address emerging threats.

Read the paper · More papers on PaperTik