Design Issues of the Side-Channel Attacks Protecting Scheme in Cloud Computing Environment
作者:Shin-Jer Yang* and Chia-Chi Yen (楊欣哲*,顏家麒)
Journal of Internet Technology (SCI)
出版:May 2020
The computing resources can be utilized and shared with other VMs on the same physical machine, thus there exists information security in cloud computing. Cloud services such as IaaS, PaaS and SaaS can employ the multi-tenancy control to accomplish the applications independence and data isolation for different tenants. The SCA attacker can break into the shared computing resources and steal stored data of other users on the physical machine, which results in data leakage and theft. Therefore, we examine and fix the security issues of current CP-SCA to propose new CRDPS scheme for enhancing defense capability of SCA.
The CRDPS can monitor the ICMP and TCP SYN packets to determine whether the sender is a SCA attacker. Then, we perform some simulations using UNB CIC Dataset to analyze and compare the CRDPS and CP-SCA schemes in terms of four KPIs. Finally, the simulation results indicate that the CRDPS has a better detection rate, higher accuracy ratio, and system throughput than the CP-SCA about 8.51%, 41.36%, and 251 packets respectively, but there is a 4.28% overhead in average processing time. Consequently, the proposed CRDPS can accurately identify the attackers to harden the security and enhance the total quality in cloud services, especially in SaaS.
Keywords— Cloud Computing; Side-Channel Attacks; ICMP; TCP SYN; Co-Residency Detection
類別 | 標題 | 登刊日期 |
校園頭條 | 賀!商學院育成中心彭仁鴻執行長 獲管理界最高榮譽「呂鳳章先生紀念獎章」 | 10/28/2024 |
校園頭條 | 恭賀李韋宏學長 榮獲第十二屆傑出大陸台商創新經營獎 | 11/22/2024 |
校園頭條 | 全國資訊創新競賽 東吳資管系再創佳績 | 11/21/2024 |
校園頭條 | 校級赴外交換研修說明暨分享會 鼓勵同學赴海外研修 | 11/21/2024 |
校園頭條 | 韌性校園 永續大學成果展暨AI黑客松競賽 展現高教深耕計畫豐碩成果 | 11/21/2024 |