跳到主要导航 跳到搜索 跳到主要内容

TCP DDOS attack detection on the host in the KVM virtual machine environment

  • Xi'an Jiaotong University
  • The Key Laboratory of Computer Network

科研成果: 书/报告/会议事项章节会议稿件同行评审

6 引用 (Scopus)

摘要

Analyze the disadvantages of KVM original network connection modes, and design the third network connection mode: NAT + Bridge mode. For the malicious virtual machines in user mode are difficult to detect and locate in normal way, the article proposes a strategy for detecting TCP DDOS attack based on an improved CUSUM algorithm in the KVM. This strategy detects attack of virtual machines in user mode indirectly by treating the user mode as an independent virtual machine, and determine the suspicious virtual machines in accordance with the abnormal behavior of the process, and then dynamically migrate the suspicious virtual machine to a independent NAT + bridged network environment, then detect the attack of every virtual machine in the independent network environment based on the improved CUSUM algorithm.

源语言英语
主期刊名Proceedings - 2012 IEEE/ACIS 11th International Conference on Computer and Information Science, ICIS 2012
出版商IEEE Computer Society
62-67
页数6
ISBN(印刷版)9780769546940
DOI
出版状态已出版 - 2012
活动11th IEEE/ACIS International Conference on Computer and Information Science, ICIS 2012 - Shanghai, 中国
期限: 30 5月 20121 6月 2012

出版系列

姓名Proceedings - 2012 IEEE/ACIS 11th International Conference on Computer and Information Science, ICIS 2012

会议

会议11th IEEE/ACIS International Conference on Computer and Information Science, ICIS 2012
国家/地区中国
Shanghai
时期30/05/121/06/12

学术指纹

探究 'TCP DDOS attack detection on the host in the KVM virtual machine environment' 的科研主题。它们共同构成独一无二的学术指纹。

引用此