NASA Logo

NTRS

NTRS - NASA Technical Reports Server

Back to Results
Detecting Distributed SQL Injection Attacks in a Eucalyptus Cloud EnvironmentThe cloud computing environment offers malicious users the ability to spawn multiple instances of cloud nodes that are similar to virtual machines, except that they can have separate external IP addresses. In this paper we demonstrate how this ability can be exploited by an attacker to distribute his/her attack, in particular SQL injection attacks, in such a way that an intrusion detection system (IDS) could fail to identify this attack. To demonstrate this, we set up a small private cloud, established a vulnerable website in one instance, and placed an IDS within the cloud to monitor the network traffic. We found that an attacker could quite easily defeat the IDS by periodically altering its IP address. To detect such an attacker, we propose to use multi-agent plan recognition, where the multiple source IPs are considered as different agents who are mounting a collaborative attack. We show that such a formulation of this problem yields a more sophisticated approach to detecting SQL injection attacks within a cloud computing environment.
Document ID
20130011364
Acquisition Source
Stennis Space Center
Document Type
Conference Paper
Authors
Kebert, Alan
(University of Southern Mississippi Hattiesburg, MS, United States)
Barnejee, Bikramjit
(University of Southern Mississippi Hattiesburg, MS, United States)
Solano, Juan
(University of Southern Mississippi Hattiesburg, MS, United States)
Solano, Wanda
(NASA Stennis Space Center Stennis Space Center, MS, United States)
Date Acquired
August 27, 2013
Publication Date
July 22, 2013
Subject Category
Computer Programming And Software
Report/Patent Number
EB-2013-03-00040-SSC
Meeting Information
Meeting: SAM 2013 International Conference on Security and Management
Location: Las Vegas, NV
Country: United States
Start Date: July 22, 2013
End Date: July 25, 2013
Funding Number(s)
CONTRACT_GRANT: NNS08AA83B
Distribution Limits
Public
Copyright
Public Use Permitted.
No Preview Available