Cloud Protection Node for Internal DDoS Attack Prevention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current DDoS prevention mechanisms are ineffective in addressing attacks between virtual machines within a cloud system, leaving cloud systems vulnerable to internal DDoS attacks.
Innovation Solution
A protection node is deployed in the cloud system to monitor data traffic, extract abnormal data streams, and send them to a traffic cleaning apparatus for cleaning, ensuring only cleaned data streams are input into virtual machines, thereby preventing both external and internal DDoS attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing DDoS prevention mechanisms are used, then external DDoS attacks are prevented, but internal DDoS attacks between virtual machines in the cloud system remain vulnerable
Solution Approach 1:
The protection node is designed to handle multiple types of DDoS attacks uniformly - both external attacks from outside the cloud system and internal attacks between virtual machines within the cloud system. The node monitors data traffic from all sources and applies consistent detection and cleaning mechanisms, making the DDoS prevention capability universally applicable across different attack scenarios without requiring separate specialized systems.
2Reliability
If a protection node is deployed to monitor all data traffic, then internal DDoS attacks are detected, but system complexity increases
Solution Approach 1:
The protection node functions as an intermediary component positioned between the network interface and the virtual machine. It intercepts data traffic, performs monitoring and analysis, and then forwards cleaned traffic to the virtual machine. This intermediary role allows centralized monitoring and processing of traffic patterns without requiring complex distributed monitoring across all virtual machines, simplifying the overall system architecture while maintaining effective internal attack detection.
Data Source
Figure 1a~1b
Figure 1c~1d
Figure 2
AI summary
A method, an apparatus and a system for preventing DDos attacks in a cloud system are disclosed. The method for preventing DDos attacks in a cloud system includes: monitoring, by a protection node in a cloud computing system, data traffic input into virtual machines, where the cloud computing system includes the protection node and multiple virtual machines, and data streams communicated between the virtual machines pass through the protection node; extracting data streams to be input into virtual machines if it is detected that the data traffic input into the virtual machines is abnormal; sending the extracted data streams to a traffic cleaning apparatus for cleaning; receiving the data streams cleaned by the traffic cleaning apparatus; and inputting the cleaned data streams into the virtual machines. The technical solutions provided in the embodiments of the present invention can effectively prevent DDos attacks between virtual machines in the cloud system.