2019 · Journal of Hardware and Systems Security

Machine Learning-Based EDoS Attack Detection Technique Using Execution Trace Analysis

Hossein Abbasi | Naser Ezzati-Jivan | Martine Bellaiche | Chamseddine Talhi | Michel R. Dagenais

Evidence basis: full-text-reviewed · Review status: catalog-reviewed; paper-author approval pending

anomaly-detection kernel-tracing machine-learning performance-analysis resource-analysis system-tracing

Economic Denial of Sustainability EDoS DDoS cloud computing execution trace analysis LTTng QEMU KVM Apache MySQL HTTPFlooder LoadRunner WEKA multilayer perceptron SVM Snort

Core contribution: The paper combines execution-trace and virtual-machine metrics with machine learning to detect EDoS behavior and restrict resource expansion to apparently normal VMs.

Catalog abstract summary

Economic Denial of Sustainability (EDoS) attacks can cause cloud customers to pay for malicious resource consumption. The paper proposes a framework that learns normal and abnormal virtual-machine behavior and allocates extra resources only to VMs classified as normal, limiting attack propagation and resource misuse.

Source: Public accepted-manuscript PDF reviewed locally; abstract paraphrased for this catalog.

Problem and motivation

EDoS attacks can make a pay-per-use cloud allocate additional resources to malicious traffic, causing cost escalation; packet-level similarity makes simple traffic rules inadequate.

Method and contribution

A hypervisor/VM monitoring framework collects an 18-feature execution/resource profile with LTTng and standard host tools, updates normal behavior with an exponential moving average, classifies traffic with a generic ML decision unit, and allocates extra resources only to traffic classified as normal. It also compares attack-specific C1/C2/C3 baselines with WEKA MLP and SMO/SVM models.

Findings and evidence

In the stated two-VM experiment, MLP reported 97.06% correct traffic and SMO/SVM reported no incorrect test instances under the 65/35 split. The framework is plotted above Snort in an approximate comparison, but mixed attacks reduce accuracy and the paper supplies no public corpus size or independent benchmark.

Limitations and future directions

Limitations: OS, kernel, hardware, corpus size, and public dataset identifier are unknown. The evaluation uses a small controlled setup and attack generators/tools; the reported test percentages should not be generalized to production traffic. Simultaneous attack classes are explicitly difficult.

Future work: Weight metrics, predict/detect additional attack classes automatically, add real-world traffic, and expand the feature set.

Sources and identifiers

When to cite this paper

Cite this paper when your work uses or compares an 18-feature VM resource/traffic profile used to gate EDoS-related resource allocation.

Citation

BibTeX
@article{ezzatiJivan2019machinelearning,
  author = {Hossein Abbasi and Naser Ezzati-Jivan and Martine Bellaiche and Chamseddine Talhi and Michel R. Dagenais},
  title = {Machine Learning-Based EDoS Attack Detection Technique Using Execution Trace Analysis},
  year = {2019},
  journal = {Journal of Hardware and Systems Security},
  volume = {3},
  number = {2},
  pages = {164-176},
  publisher = {Springer Science and Business Media LLC},
  issn = {2509-3428, 2509-3436},
  doi = {10.1007/s41635-018-0061-2},
  url = {https://doi.org/10.1007/s41635-018-0061-2}
}
Other citation formats for Word and reference managers
APA 7
Abbasi, H., Ezzati-Jivan, N., Bellaiche, M., Talhi, C., & Dagenais, M. R. (2019). Machine Learning-Based EDoS Attack Detection Technique Using Execution Trace Analysis. Journal of Hardware and Systems Security, 3(2), 164-176. https://doi.org/10.1007/s41635-018-0061-2
IEEE
H. Abbasi, N. Ezzati-Jivan, M. Bellaiche, C. Talhi, and M. R. Dagenais, "Machine Learning-Based EDoS Attack Detection Technique Using Execution Trace Analysis," Journal of Hardware and Systems Security, vol. 3, no. 2, pp. 164-176, 2019, doi: 10.1007/s41635-018-0061-2

Readable Markdown record · JSON record · Download RIS