IJMIE Volume 3, Issue 9 ISSN: 2249-0558
__________________________________________________________
A Monthly Double-Blind Peer Reviewed Refereed Open Access International e-Journal - Included in the International Serial Directories
Indexed & Listed at: Ulrich's Periodicals Directory ©, U.S.A., Open J-Gage as well as in Cabell’s Directories of Publishing Opportunities, U.S.A.
International Journal of Management, IT and Engineering
http://www.ijmra.us
197
September
2013
Secure Network ID and Attack Measure
Selection in Virtual Network
S.Uvaraj
S.Suresh
Abstract
Cloud security is one of most important issues that has attracted a lot of research and
development effort in past few years. Particularly, attackers can explore vulnerabilities of a
cloud system and compromise virtual machines to deploy further large-scale Distributed Denial-
of-Service (DDoS). DDoS attacks usually involve early stage actions such as multi-step
exploitation, low frequency vulnerability scanning, and compromising identified vulnerable
virtual machines as zombies, and finally DDoS attacks through the compromised zombies.
Within the cloud system, especially the Infrastructure-as a-Service (IaaS) clouds, the detection of
zombie exploration attacks is extremely difficult. This is because cloud users may install
vulnerable applications on their virtual machines. To prevent vulnerable virtual machines from
being compromised in the cloud, we propose a multi phase distributed vulnerability detection,
measurement, and countermeasure selection mechanism called NICE, which is built on attack
graph based analytical models and reconfigurable virtual network-based countermeasures. The
proposed framework leverages Open Flow network programming APIs to build a monitor and
control plane over distributed programmable virtual switches in order to significantly improve
attack detection and mitigate attack consequences. The system and security evaluations
demonstrate the efficiency and effectiveness of the proposed solution.
Keywords - Network Security, Cloud Computing, Intrusion Detection, Attack Graph, Zombie
Detection
M.E/CSE, Arulmigu Meenakshi Amman College of Engineering, Kanchipuram, India
B.Tech/IT, Sri Venkateswara College of Engineering, Chennai, India