Toward deceiving the intrusion attacks in containerized cloud environment using virtual private cloud-based moving target defense

被引:1
|
作者
Hyder, Muhammad Faraz [1 ]
Ahmed, Waqas [2 ]
Ahmed, Maaz [2 ]
机构
[1] NED Univ Engn & Technol, Natl Ctr Cyber Secur, Dept Software Engn, Karachi 75270, Pakistan
[2] NED Univ Engn & Technol, Dept Comp Sci & Informat Technol, Karachi, Pakistan
来源
CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE | 2023年 / 35卷 / 05期
关键词
containerization; intrusion attacks; Kubernetes; moving target defense; virtual private cloud; SECURITY ISSUES;
D O I
10.1002/cpe.7549
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
The container-based cloud has its distinct security challenges. In this article, moving target defense (MTD) is used to increase the cost and effort of the attacker to exploit resources and follow an attack path to compromise the critical resources in a container-based cloud. The existing MTD mechanisms for cloud have not focused on intruder prevention inside containerized environment. The proposed solution is one of its kind that utilizes resource movement inside and across the virtual private network in the cloud to deceive intruders. The framework continuously changes the target/container to increase confusion about the routing path, so attackers cannot follow the simple attack path. This obscure cloud architecture increases the delay in attack and gives system/network administrators significant time to use Intrusion Detection mechanisms for countering the attack. The proposed scheme is implemented on the Google Cloud Platform (GCP) by using an extensive network of nodes hosting the stateful pods that are created and destroyed periodically. The experimental analysis confirmed that the proposed scheme substantially increased the attack path length and added obscurity at a low computation cost. However, as per experiments, implementing the proposed scheme in GCP slightly increases the dollar cost.
引用
收藏
页数:18
相关论文
共 50 条
  • [21] Improving intrusion detection in cloud-based healthcare using neural network
    Patel, Sagarkumar K.
    BIOMEDICAL SIGNAL PROCESSING AND CONTROL, 2023, 83
  • [22] NEARBY Platform for Detecting Asteroids in Astronomical Images Using Cloud-based Containerized Applications
    Bacu, Victor
    Sabou, Adrian
    Stefanut, Teodor
    Gorgan, Dorian
    Vaduvescu, Ovidiu
    2018 IEEE 14TH INTERNATIONAL CONFERENCE ON INTELLIGENT COMPUTER COMMUNICATION AND PROCESSING (ICCP), 2018, : 371 - 376
  • [23] WORK-IN-PROGRESS: CREATING AN INTRUSION DETECTION EXPERIMENTAL ENVIRONMENT USING CLOUD-BASED VIRTUALIZATION TECHNOLOGY
    Jones, John M.
    Chou, Te-Shun
    2012 ASEE ANNUAL CONFERENCE, 2012,
  • [24] Private Cloud based Solution for the Implementation of a Virtual and Personal Learning Environment
    Gao, Jimin
    PROCEEDINGS OF THE 2015 INTERNATIONAL CONFERENCE ON AUTOMATION, MECHANICAL CONTROL AND COMPUTATIONAL ENGINEERING, 2015, 124 : 1903 - 1906
  • [25] Cloud-based smart environment using internet of things (IoT)
    Lydia E.L.
    Gummadi J.M.
    Nukapeyi S.
    Lingamgunta S.
    Mohan A.K.
    Daniel R.
    Lecture Notes on Data Engineering and Communications Technologies, 2021, 66 : 217 - 225
  • [26] Cloud-based Virtual Desktop Environment for Advanced Online Master's Courses
    Moser, Steffen
    Groeger, Gabriele
    Krapp, Fabian
    Slomka, Frank
    Baertele, Stefanie
    Schumacher, Hermann
    Wunderlich, Kathrin
    2014 INTERNATIONAL CONFERENCE ON WEB AND OPEN ACCESS TO LEARNING (ICWOAL), 2014,
  • [27] FDA3: Federated Defense Against Adversarial Attacks for Cloud-Based IIoT Applications
    Song, Yunfei
    Liu, Tian
    Wei, Tongquan
    Wang, Xiangfeng
    Tao, Zhe
    Chen, Mingsong
    IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2021, 17 (11) : 7830 - 7838
  • [28] Cloud-Based Data Exchange and Messaging Platform Implementation for Virtual Factory Environment
    Hao, Y.
    Helo, P.
    Shamsuzzoha, A.
    2015 IEEE INTERNATIONAL CONFERENCE ON INDUSTRIAL ENGINEERING AND ENGINEERING MANAGEMENT (IEEM), 2015, : 426 - 430
  • [29] ADRCN: A Framework to Detect and Mitigate Malicious Insider Attacks in Cloud-Based Environment on IaaS
    Oberoi, Priya
    Mittal, Sumit
    Gujral, Rajneesh Kumar
    INTERNATIONAL JOURNAL OF MATHEMATICAL ENGINEERING AND MANAGEMENT SCIENCES, 2019, 4 (03) : 654 - 670
  • [30] An Experimental Evaluation of A Cloud-based Virtual Computer Laboratory Using OpenStack
    Kabiri, Mohammad Nazim
    Wannous, Muhammad
    2017 6TH IIAI INTERNATIONAL CONGRESS ON ADVANCED APPLIED INFORMATICS (IIAI-AAI), 2017, : 667 - 672