A Cooperative and Hybrid Network Intrusion Detection Framework in Cloud Computing Based on Snort and Optimized Back Propagation Neural Network

被引:27
|
作者
Chiba, Z. [1 ]
Abghour, N. [1 ]
Moussaid, K. [1 ]
El Omri, A. [1 ]
Rida, M. [1 ]
机构
[1] Hassan II Univ Casablanca, Team Modeling & Optimizat Mobile Serv, Fac Sci, Casablanca 20100, Morocco
来源
7TH INTERNATIONAL CONFERENCE ON AMBIENT SYSTEMS, NETWORKS AND TECHNOLOGIES (ANT 2016) / THE 6TH INTERNATIONAL CONFERENCE ON SUSTAINABLE ENERGY INFORMATION TECHNOLOGY (SEIT-2016) / AFFILIATED WORKSHOPS | 2016年 / 83卷
关键词
Cloud computing; Network intrusion detection; Back-propagation neural network; Snort; Optimization algorithm;
D O I
10.1016/j.procs.2016.04.249
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Cloud computing provides a framework for supporting end users easily attaching powerful services and applications through Internet. To give secure and reliable services in cloud computing environment is an important issue. Providing security requires more than user authentication with passwords or digital certificates and confidentiality in data transmission, because it is vulnerable and prone to network intrusions that affect confidentiality, availability and integrity of Cloud resources and offered services. To detect DoS attack and other network level malicious activities in Cloud, use of only traditional firewall is not an efficient solution. In this paper, we propose a cooperative and hybrid network intrusion detection system (CH-NIDS) to detect network attacks in the Cloud environment by monitoring network traffic, while maintaining performance and service quality. In our NIDS framework, we use Snort as a signature based detection to detect known attacks, while for detecting network anomaly, we use Back-Propagation Neural network (BPN). By applying snort prior to the BPN classifier, BPN has to detect only unknown attacks. So, detection time is reduced. To solve the problem of slow convergence of BPN and being easy to fall into local optimum, we propose to optimize the parameters of it by using an optimization algorithm in order to ensure high detection rate, high accuracy, low false positives and low false negatives with affordable computational cost. In addition, in this framework, the IDSs operate in cooperative way to oppose the DoS and DDoS attacks by sharing alerts stored in central log. In this way, unknown attacks that were detected by any IDS can easily be detected by others IDSs. This also helps to reduce computational cost for detecting intrusions at others IDS, and improve detection rate in overall the Cloud environment. (C) 2016 The Authors. Published by Elsevier B.V.
引用
收藏
页码:1200 / 1206
页数:7
相关论文
共 50 条
  • [31] IoT-based blockchain intrusion detection using optimized recurrent neural network
    Saravanan, V.
    Madiajagan, M.
    Rafee, Shaik Mohammad
    Sanju, P.
    Rehman, Tasneem Bano
    Pattanaik, Balachandra
    MULTIMEDIA TOOLS AND APPLICATIONS, 2024, 83 (11) : 31505 - 31526
  • [32] Chaotic Metaheuristics with Multi-Spiking Neural Network Based Cloud Intrusion Detection
    Yamin, Mohammad
    Bajaba, Saleh
    AlKubaisy, Zenah Mahmoud
    CMC-COMPUTERS MATERIALS & CONTINUA, 2023, 74 (03): : 6101 - 6118
  • [33] A Transformer-based network intrusion detection approach for cloud security
    Long, Zhenyue
    Yan, Huiru
    Shen, Guiquan
    Zhang, Xiaolu
    He, Haoyang
    Cheng, Long
    JOURNAL OF CLOUD COMPUTING-ADVANCES SYSTEMS AND APPLICATIONS, 2024, 13 (01):
  • [34] A Transformer-based network intrusion detection approach for cloud security
    Zhenyue Long
    Huiru Yan
    Guiquan Shen
    Xiaolu Zhang
    Haoyang He
    Long Cheng
    Journal of Cloud Computing, 13
  • [35] BNID: A Behavior-based Network Intrusion Detection at Network-Layer in Cloud Environment
    Ghanshala, Kamal Kumar
    Mishra, Preeti
    Joshi, R. C.
    Sharma, Sachin
    2018 FIRST INTERNATIONAL CONFERENCE ON SECURE CYBER COMPUTING AND COMMUNICATIONS (ICSCCC 2018), 2018, : 100 - 105
  • [36] RID-Cloud: Spectral Recurrent Neural Network-Based Intrusion Detection in Cloud Environment
    Aarthi, G.
    Priya, S. Sharon
    Banu, W. Aisha
    IETE JOURNAL OF RESEARCH, 2025, 71 (02) : 499 - 510
  • [37] Distributed Denial of Service Defense on Cloud Computing Based on Network Intrusion Detection System: Survey
    Samkari, Esraa
    Alsuwat, Hatim
    INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2022, 22 (06): : 67 - 74
  • [38] An Intrusion Detection Method for Enterprise Network Based on Backpropagation Neural Network
    Chen F.
    Cheng R.
    Zhu Y.
    Miao S.
    Zhou L.
    Ingenierie des Systemes d'Information, 2020, 25 (03): : 377 - 382
  • [39] Study of economic management forecast and optimized resource allocation based on cloud computing and neural network
    Pinzhen He
    EURASIP Journal on Wireless Communications and Networking, 2020
  • [40] Study of economic management forecast and optimized resource allocation based on cloud computing and neural network
    He, Pinzhen
    EURASIP JOURNAL ON WIRELESS COMMUNICATIONS AND NETWORKING, 2020, 2020 (01)