Attack Prediction Models for Cloud Intrusion Detection Systems

被引:5
作者
Kholidy, Hisham A. [1 ,3 ]
Erradi, Abdelkarim [1 ]
Abdelwahed, Sherif [2 ]
机构
[1] Qatar Univ, Coll Engn, Dept Comp Sci & Engn, Doha, Qatar
[2] Mississippi State Univ, Elect & Comp Engn, Starkville, MS USA
[3] Fayoum Univ, Fac Comp & Informat, Al Fayyum, Egypt
来源
2014 2ND INTERNATIONAL CONFERENCE ON ARTIFICIAL INTELLIGENCE, MODELLING AND SIMULATION | 2014年
关键词
Cloud computing; intrusion prediction; multi-staged attacks; HMM; VMM; Probability Suffix Tree; HoltWinter;
D O I
10.1109/AIMS.2014.64
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
In spite of the functional and economic benefits of the cloud-computing systems, they also expose entirely several attacks. Most of the current cloud security technologies do not provide early warnings about such attacks. The early warnings give the cloud administrator or the auto response controller ample time to take preventive measures. This paper discusses our three prediction models that are integrated to our Autonomic Cloud Intrusion Detection Framework (ACIDF) namely, The Finite State Hidden Markov prediction model (FSHMPM), The Finite Context Prediction Model (FCPM) that uses a Variable Order Markov Model (VMM) with a Probabilistic Suffix Tree (PST), and HoltWinter Prediction Model (HWPM). We compare these models and highlight the pros and cons of each one. The prediction models were evaluated against DARPA 2000 dataset. The FSHMPM has successfully fired the early warnings 39.6 minutes before the launching of the LLDDoS1.0 attack. The FCPM has successfully fired the early warnings 58.98 minutes before the launching of the same attack. The HWPM has an error rate of 42.07% for HTTP flow forecast and 44.02% for FTP one.
引用
收藏
页码:270 / 275
页数:6
相关论文
共 17 条
  • [1] [Anonymous], 2007, RFC4765
  • [2] Bace R., 2001, NIST Special Publication on Intrusion Detection Systems
  • [3] Chen Q., PARALLEL DISTRIBUTED
  • [4] Ekberg Jarkko, 2011, P 6 INT C INT TECHN
  • [5] Fava D. S., PROJECTING CYBER ATT, P1
  • [6] Gao F, 2003, CCECE 2003: CANADIAN CONFERENCE ON ELECTRICAL AND COMPUTER ENGINEERING, VOLS 1-3, PROCEEDINGS, P893
  • [7] Haslum K., 2008, 33 IEEE C LOC COMP N
  • [8] Kephart J. O., 2004, J ROYAL STAT SOC C, V27, P264
  • [9] Kholidy H. A., 2012, INT J CLOUD COMPUTIN, V2
  • [10] Kholidy Hisham A., 2014, 12 IEEE INT C DEP AU