Toward deceiving the intrusion attacks in containerized cloud environment using virtual private cloud-based moving target defense

被引:1
|
作者
Hyder, Muhammad Faraz [1 ]
Ahmed, Waqas [2 ]
Ahmed, Maaz [2 ]
机构
[1] NED Univ Engn & Technol, Natl Ctr Cyber Secur, Dept Software Engn, Karachi 75270, Pakistan
[2] NED Univ Engn & Technol, Dept Comp Sci & Informat Technol, Karachi, Pakistan
来源
CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE | 2023年 / 35卷 / 05期
关键词
containerization; intrusion attacks; Kubernetes; moving target defense; virtual private cloud; SECURITY ISSUES;
D O I
10.1002/cpe.7549
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
The container-based cloud has its distinct security challenges. In this article, moving target defense (MTD) is used to increase the cost and effort of the attacker to exploit resources and follow an attack path to compromise the critical resources in a container-based cloud. The existing MTD mechanisms for cloud have not focused on intruder prevention inside containerized environment. The proposed solution is one of its kind that utilizes resource movement inside and across the virtual private network in the cloud to deceive intruders. The framework continuously changes the target/container to increase confusion about the routing path, so attackers cannot follow the simple attack path. This obscure cloud architecture increases the delay in attack and gives system/network administrators significant time to use Intrusion Detection mechanisms for countering the attack. The proposed scheme is implemented on the Google Cloud Platform (GCP) by using an extensive network of nodes hosting the stateful pods that are created and destroyed periodically. The experimental analysis confirmed that the proposed scheme substantially increased the attack path length and added obscurity at a low computation cost. However, as per experiments, implementing the proposed scheme in GCP slightly increases the dollar cost.
引用
收藏
页数:18
相关论文
共 50 条
  • [41] Cloud-based Real-time Network Intrusion Detection Using Deep Learning
    Parampottupadam, Santhosh
    Moldovann, Arghir-Nicolae
    2018 INTERNATIONAL CONFERENCE ON CYBER SECURITY AND PROTECTION OF DIGITAL SERVICES (CYBER SECURITY), 2018,
  • [42] Cloud-Based Cyber-Physical Intrusion Detection for Vehicles Using Deep Learning
    Loukas, George
    Tuan Vuong
    Heartfield, Ryan
    Sakellari, Georgia
    Yoon, Yongpil
    Gan, Diane
    IEEE ACCESS, 2018, 6 : 3491 - 3508
  • [43] Mitigating Crossfire Attacks using SDN-based Moving Target Defense
    Aydeger, Abdullah
    Saputro, Nico
    Akkaya, Kemal
    Rahman, Mohammad
    2016 IEEE 41ST CONFERENCE ON LOCAL COMPUTER NETWORKS (LCN), 2016, : 627 - 630
  • [44] Cloud-based Virtual Desktop Service Using Lightweight Network Display Protocol
    Kim, Sunwook
    Choi, Jihyeok
    Kim, Seongwoon
    Kim, Hagyoung
    2016 INTERNATIONAL CONFERENCE ON INFORMATION NETWORKING (ICOIN), 2016, : 244 - 248
  • [45] Defense Technique against Spoofing Attacks using Reliable ARP Table in Cloud Computing Environment
    Kang, Hyo Sung
    Son, Jae Hyeok
    Hong, Choong Seon
    2015 17TH ASIA-PACIFIC NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM APNOMS, 2015, : 592 - 595
  • [46] Moving Target Defense-Based Denial-of-Service Mitigation in Cloud Environments: A Survey
    Minh Nguyen
    Debroy, Saptarshi
    SECURITY AND COMMUNICATION NETWORKS, 2022, 2022
  • [47] vSocial: a cloud-based system for social virtual reality learning environment applications in special education
    Sai Shreya Nuguri
    Prasad Calyam
    Roland Oruche
    Aniket Gulhane
    Samaikya Valluripally
    Janine Stichter
    Zhihai He
    Multimedia Tools and Applications, 2021, 80 : 16827 - 16856
  • [48] Counteracting security attacks in virtual machines in the cloud using property based attestation
    Varadharajan, Vijay
    Tupakula, Udaya
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2014, 40 : 31 - 45
  • [49] vSocial: a cloud-based system for social virtual reality learning environment applications in special education
    Nuguri, Sai Shreya
    Calyam, Prasad
    Oruche, Roland
    Gulhane, Aniket
    Valluripally, Samaikya
    Stichter, Janine
    He, Zhihai
    MULTIMEDIA TOOLS AND APPLICATIONS, 2021, 80 (11) : 16827 - 16856
  • [50] Study of Immune-Based Intrusion Detection Technology in Virtual Machines for Cloud Computing Environment
    Zhang, Ruirui
    Xiao, Xin
    MOBILE INFORMATION SYSTEMS, 2017, 2017