Protecting VNF services with smart online behavior anomaly detection method

被引:3
作者
Cheng, Yuxia [1 ]
Yao, Huijuan [2 ]
Wang, Yu [3 ]
Xiang, Yang [4 ]
Li, Hongpei [2 ]
机构
[1] Hangzhou Dianzi Univ, 1 Ave 2, Hangzhou, Zhejiang, Peoples R China
[2] Huawei Technol Co LTD, Shield Lab, Beijing, Peoples R China
[3] Guangzhou Univ, Guangzhou Higher Educ Mega Ctr, 230 Wai Huan Xi Rd, Guangzhou, Guangdong, Peoples R China
[4] Swinburne Univ Technol, John St, Hawthorn, Vic, Australia
来源
FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE | 2019年 / 95卷
关键词
NFV; Behavior model; HMM; Anomaly detection; OpenStack; INTRUSION DETECTION SYSTEM; HIDDEN MARKOV MODEL; PROBABILISTIC FUNCTIONS; NETWORK;
D O I
10.1016/j.future.2018.12.058
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Network Function Virtualization (NFV) is an emerging technology that allows network operators to deploy their Virtualized Network Functions (VNFs) on low-cost commodity servers in the cloud data center. The VNFs, such as virtual routers, firewalls etc., that typically control and transmit critical network packages, require strong security guarantees. However, detecting malicious or malfunctioning VNFs are challenging, as the behaviors of VNFs are dynamic and complex due to the changing network traffics in the cloud. In this paper, we propose a smart and efficient Hidden Markov Model based anomaly detection system (named vGuard) to protect online VNF services in the cloud. A general multivariate HMM model is proposed to profile the normal VNF behavior patterns. Using the VNF behavior model trained with normal observation sequences, vGuard can effectively detect abnormal behaviors online. vGuard is a general framework that can train different types of VNF behavior models. We implement the vGuard prototype in the OpenStack platform. Two types of VNF models, virtual router and virtual firewall, are trained using real normal network traffics in our experiment evaluation. A collection of abnormal attack cases are tested on the VNFs that showed the effectiveness of vGuard in detecting VNF behavior anomalies. (C) 2019 Elsevier B.V. All rights reserved.
引用
收藏
页码:265 / 276
页数:12
相关论文
共 48 条
[1]  
Abraham A., 2007, Int. J. Netw. Secur, V4, P328
[2]   Mutual information-based feature selection for intrusion detection systems [J].
Amiri, Fatemeh ;
Yousefi, MohammadMahdi Rezaei ;
Lucas, Caro ;
Shakery, Azadeh ;
Yazdani, Nasser .
JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2011, 34 (04) :1184-1199
[3]  
Amor S., 2004, ACM Symp. Appl. Comput, P420, DOI DOI 10.1145/967900.967989
[4]  
[Anonymous], 2016, Tech. Rep.,
[5]   HMMPayl: An intrusion detection system based on Hidden Markov Models [J].
Ariu, Davide ;
Tronci, Roberto ;
Giacinto, Giorgio .
COMPUTERS & SECURITY, 2011, 30 (04) :221-241
[6]   GROWTH TRANSFORMATIONS FOR FUNCTIONS ON MANIFOLDS [J].
BAUM, LE ;
SELL, GR .
PACIFIC JOURNAL OF MATHEMATICS, 1968, 27 (02) :211-&
[7]   STATISTICAL INFERENCE FOR PROBABILISTIC FUNCTIONS OF FINITE STATE MARKOV CHAINS [J].
BAUM, LE ;
PETRIE, T .
ANNALS OF MATHEMATICAL STATISTICS, 1966, 37 (06) :1554-&
[8]   AN INEQUALITY WITH APPLICATIONS TO STATISTICAL ESTIMATION FOR PROBABILISTIC FUNCTIONS OF MARKOV PROCESSES AND TO A MODEL FOR ECOLOGY [J].
BAUM, LE ;
EAGON, JA .
BULLETIN OF THE AMERICAN MATHEMATICAL SOCIETY, 1967, 73 (03) :360-&
[9]  
Benferhat Salem, 2008, 2008 IEEE 32nd International Computer Software and Applications Conference (COMPSAC), P704, DOI 10.1109/COMPSAC.2008.213
[10]   EXPOSURE: A Passive DNS Analysis Service to Detect and Report Malicious Domains [J].
Bilge, Leyla ;
Sen, Sevil ;
Balzarotti, Davide ;
Kirda, Engin ;
Kruegel, Christopher .
ACM TRANSACTIONS ON INFORMATION AND SYSTEM SECURITY, 2014, 16 (04)