@inproceedings{3faf813d0ae148c6a0c03de38c4f41f4,
title = "TCP DDOS attack detection on the host in the KVM virtual machine environment",
abstract = "Analyze the disadvantages of KVM original network connection modes, and design the third network connection mode: NAT + Bridge mode. For the malicious virtual machines in user mode are difficult to detect and locate in normal way, the article proposes a strategy for detecting TCP DDOS attack based on an improved CUSUM algorithm in the KVM. This strategy detects attack of virtual machines in user mode indirectly by treating the user mode as an independent virtual machine, and determine the suspicious virtual machines in accordance with the abnormal behavior of the process, and then dynamically migrate the suspicious virtual machine to a independent NAT + bridged network environment, then detect the attack of every virtual machine in the independent network environment based on the improved CUSUM algorithm.",
keywords = "Improved CUSUM algorithm, KVM, TCP DDOS attack, Virtual machine",
author = "Zhuang Wei and Gui Xiaolin and Wei, \{Huang Ru\} and Yu Si",
year = "2012",
doi = "10.1109/ICIS.2012.105",
language = "英语",
isbn = "9780769546940",
series = "Proceedings - 2012 IEEE/ACIS 11th International Conference on Computer and Information Science, ICIS 2012",
publisher = "IEEE Computer Society",
pages = "62--67",
booktitle = "Proceedings - 2012 IEEE/ACIS 11th International Conference on Computer and Information Science, ICIS 2012",
note = "11th IEEE/ACIS International Conference on Computer and Information Science, ICIS 2012 ; Conference date: 30-05-2012 Through 01-06-2012",
}