Detecting TCP SYN Flood Attack in the Cloud - Volume 12 Number 7 (July. 2017) - JSOFTWARE
Volume 12 Number 7 (July. 2017)
Home > Archive > 2017 > Volume 12 Number 7 (July. 2017) >
JSW 2017 Vol.12(7): 493-506 ISSN: 1796-217X
doi: 10.17706/jsw.12.7.493-506

Detecting TCP SYN Flood Attack in the Cloud

Raneel Kumar1*, Sunil Lal2, Alok Sharma1,3
1University of the South Pacific, Fiji.
2Massey University, New Zealand.
3Griffith University, Australia.


Abstract—In this paper, an approach to protecting virtual machines (VMs) against TCP SYN flood attack in a cloud environment is proposed. An open source cloud platform Eucalyptus is deployed and experimentation is carried out on this setup. We investigate attacks emanating from one VM to another in a multi-tenancy cloud environment. Various scenarios of the attack are executed on a webserver VM. To detect such attacks from a cloud provider’s perspective, a security mechanism involving a packet sniffer, feature extraction process, a classifier and an alerting component is proposed and implemented. We experiment with k-nearest neighbor and artificial neural network for classification of the attack. The dataset obtained from the attacks on the webserver VM is passed through the classifiers. The artificial neural network produced a F1 score of 1 with the test case simplying a 100% detection accuracy of the malicious attack traffic from legitimate traffic. The proposed security mechanism shows promising results in detecting TCP SYN flood attack behaviors in the cloud.

Index Terms—Eucalyptus cloud, denial of service attack, TCP SYN flood, artificial neural network, k-nearest neighbor.

[PDF]

Cite: Raneel Kumar, Sunil Lal, Alok Sharma, "Detecting TCP SYN Flood Attack in the Cloud," Journal of Software vol. 12, no. 7, pp. 493-506, 2017.

General Information

ISSN: 1796-217X
Frequency: Monthly
Editor-in-Chief: Prof. Antanas Verikas
Executive Editor: Ms. Yoyo Y. Zhou
Abstracting/ Indexing: DBLP, EBSCO, ProQuest, INSPEC, ULRICH's Periodicals Directory, WorldCat, CNKI,etc
E-mail: jsw@iap.org
  • Aug 01, 2018 News!

    Papers published in JSW Vol. 13, No. 1- Vol. 13 No. 6 have been indexed by DBLP.    [Click]

  • Aug 01, 2018 News!

    [CFP] 2018 the annual meeting of JSW Editorial Board, ICSTE 2018, will be held in Kuala Lumpur, Malaysia, October 27-29, 2018.   [Click]

  • Aug 01, 2018 News!

    Vol 13, No. 7 has been published with online version 4 original aritcles from 3 countries are published in this issue.      [Click]

  • Jun 25, 2018 News!

    The papers published in Vol.13, No. 6 have all received dois from Crossref.

  • Aug 01, 2018 News!

    The papers published in Vol.13, No. 7 have all received dois from Crossref.