ContainerGuard: A Real-Time Attack Detection System in Container-Based Big Data Platform

被引:20
作者
Wang, Yulong [1 ]
Wang, Qixu [1 ]
Chen, Xingshu [1 ]
Chen, Dajiang [2 ,3 ]
Fang, Xiaojie [4 ]
Yin, Mingyong [5 ]
Zhang, Ning [6 ]
机构
[1] Sichuan Univ, Sch Cyber Sci & Engn, Chengdu 610065, Peoples R China
[2] Univ Elect Sci & Technol China, Sch Informat & Software Engn, Chengdu 610054, Peoples R China
[3] Peng Cheng Lab, Shenzhen 518055, Peoples R China
[4] Harbin Inst Technol, Dept Elect & Informat Engn, Harbin 150001, Peoples R China
[5] China Acad Engn Phys, Inst Comp Applicat, Mianyang 621900, Sichuan, Peoples R China
[6] Univ Windsor, Dept Elect & Comp Engn, Windsor, ON N9B 3P4, Canada
基金
中国国家自然科学基金;
关键词
Containers; Big Data; Process control; Side-channel attacks; Kernel; Security; Hardware; Anomaly detection; big data platform security; container; meltdown and spectre; variational autoencoder (VAE); SIDE-CHANNEL ATTACKS; SPARK;
D O I
10.1109/TII.2020.3047416
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
As a lightweight, flexible, and high-performance operating system virtualization, containers are used to speed up the big data platform. However, due to the imperfection of the resource isolation mechanism and the property of shared kernel, the meltdown and spectre attacks can lead to information leakage of kernel space and coresident containers. In this article, a noise-resilient and real-time detection system, named ContainerGuard, is proposed to detect meltdown and spectre attacks in the container-based big data platform. ContainerGuard uses a nonintrusive manner to collect lifecycle multivariate time-series performance event data of processes in containers and then uses ensemble of variational autoencoders as generative neural networks to learn the robust representations of normal patterns. Therefore, ContainerGuard meets the urgent need for information protection in the container-based big data platform. Our evaluations using real-world datasets show that ContainerGuard achieves excellent detection performance and only introduces about 4.5% of running performance overhead to the platform.
引用
收藏
页码:3327 / 3336
页数:10
相关论文
共 50 条
  • [31] BRNADS: Big data Real-Time Node Anomaly Detection in Social Networks
    Manjunatha, H. C.
    Mohanasundaram, R.
    PROCEEDINGS OF THE 2ND INTERNATIONAL CONFERENCE ON INVENTIVE SYSTEMS AND CONTROL (ICISC 2018), 2018, : 929 - 932
  • [32] A Public Safety Deduction Framework Based on Real-Time Big Data
    Chen, Bin
    Luo, Yuyu
    Qiu, Xiaogang
    THEORY, METHODOLOGY, TOOLS AND APPLICATIONS FOR MODELING AND SIMULATION OF COMPLEX SYSTEMS, PT III, 2016, 645 : 574 - 584
  • [33] Study of CDR Real-time Query Based on Big Data Technologies
    Gao, Zhiheng
    Chen, Kang
    Bi, Lingyan
    PROGRESS IN MECHATRONICS AND INFORMATION TECHNOLOGY, PTS 1 AND 2, 2014, 462-463 : 845 - +
  • [34] Robust Anomaly Detection Algorithms for Real-time Big Data Comparison of algorithms
    Hasani, Zirije
    2017 6TH MEDITERRANEAN CONFERENCE ON EMBEDDED COMPUTING (MECO), 2017, : 449 - 454
  • [35] Construction of Lightweight Big Data Experimental Platform Based on Dockers Container
    Ren, Youli
    INTERNATIONAL JOURNAL OF INFORMATION SYSTEM MODELING AND DESIGN, 2020, 11 (03) : 100 - 113
  • [36] Real-time DDoS attack detection using FPGA
    Hoque, N.
    Kashyap, H.
    Bhattacharyya, D. K.
    COMPUTER COMMUNICATIONS, 2017, 110 : 48 - 58
  • [37] A Real-Time Autonomous Highway Accident Detection Model Based on Big Data Processing and Computational Intelligence
    Ozhayoglu, Mural
    Kucukayan, Gokhan
    Dogdu, Erdogan
    2016 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA), 2016, : 1807 - 1813
  • [38] Real time intrusion detection system for ultra-high-speed big data environments
    Rathore, M. Mazhar
    Ahmad, Awais
    Paul, Anand
    JOURNAL OF SUPERCOMPUTING, 2016, 72 (09) : 3489 - 3510
  • [39] A study on data communicating method of real time based container tracking system
    Shin, Joong Jo
    Choi, Hyung Rim
    Lee, Kang Bae
    Son, Jung Rock
    Lee, Jin Wook
    Son, Hee Mok
    International Journal of Multimedia and Ubiquitous Engineering, 2012, 7 (02): : 201 - 208
  • [40] Big Data Analytics of Geosocial Media for Planning and Real-Time Decisions
    Rathore, M. Mazhar
    Paul, Anand
    Ahmad, Awais
    Imran, Muhammad
    Guizani, Mohsen
    2017 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2017,