A Survey on Intrusion Detection Systems for Fog and Cloud Computing

被引:30
作者
Chang, Victor [1 ]
Golightly, Lewis [1 ]
Modesti, Paolo [1 ]
Xu, Qianwen Ariel [1 ]
Doan, Le Minh Thao [1 ]
Hall, Karl [1 ]
Boddu, Sreeja [2 ]
机构
[1] Teesside Univ, Sch Comp Engn & Digital Technol, Cybersecur Informat Syst & AI Res Grp, Middlesbrough TS1 3BX, Cleveland, England
[2] Poznan Univ Tech, Inst Comp Sci, PL-60965 Poznan, Poland
关键词
cloud computing; intrusion detection and prevention; security; recommendations for cloud computing and security; recommendations for network security; defense techniques; SECURITY; SERVICE; ARCHITECTURE;
D O I
10.3390/fi14030089
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The rapid advancement of internet technologies has dramatically increased the number of connected devices. This has created a huge attack surface that requires the deployment of effective and practical countermeasures to protect network infrastructures from the harm that cyber-attacks can cause. Hence, there is an absolute need to differentiate boundaries in personal information and cloud and fog computing globally and the adoption of specific information security policies and regulations. The goal of the security policy and framework for cloud and fog computing is to protect the end-users and their information, reduce task-based operations, aid in compliance, and create standards for expected user actions, all of which are based on the use of established rules for cloud computing. Moreover, intrusion detection systems are widely adopted solutions to monitor and analyze network traffic and detect anomalies that can help identify ongoing adversarial activities, trigger alerts, and automatically block traffic from hostile sources. This survey paper analyzes factors, including the application of technologies and techniques, which can enable the deployment of security policy on fog and cloud computing successfully. The paper focuses on a Software-as-a-Service (SaaS) and intrusion detection, which provides an effective and resilient system structure for users and organizations. Our survey aims to provide a framework for a cloud and fog computing security policy, while addressing the required security tools, policies, and services, particularly for cloud and fog environments for organizational adoption. While developing the essential linkage between requirements, legal aspects, analyzing techniques and systems to reduce intrusion detection, we recommend the strategies for cloud and fog computing security policies. The paper develops structured guidelines for ways in which organizations can adopt and audit the security of their systems as security is an essential component of their systems and presents an agile current state-of-the-art review of intrusion detection systems and their principles. Functionalities and techniques for developing these defense mechanisms are considered, along with concrete products utilized in operational systems. Finally, we discuss evaluation criteria and open-ended challenges in this area.
引用
收藏
页数:27
相关论文
共 57 条
[1]   Application of artificial bee colony for intrusion detection systems [J].
Aldwairi, Monther ;
Khamayseh, Yaser ;
Al-Masri, Mohammad .
SECURITY AND COMMUNICATION NETWORKS, 2015, 8 (16) :2730-2740
[2]  
ALrayes MM, 2011, IEEE INT CONF NETWOR, P71, DOI 10.1109/ICON.2011.6168509
[3]   Hypergraph clustering model-based association analysis of DDOS attacks in fog computing intrusion detection system [J].
An, Xingshuo ;
Su, Jingtao ;
Lue, Xing ;
Lin, Fuhong .
EURASIP JOURNAL ON WIRELESS COMMUNICATIONS AND NETWORKING, 2018,
[4]  
[Anonymous], 2021, SOA
[5]  
[Anonymous], White paper
[6]   Network Intrusion Detection System Using Neural Network and Condensed Nearest Neighbors with Selection of NSL-KDD Influencing Features [J].
Belgrana, Fatima Zohra ;
Benamrane, Nacera ;
Hamaida, Mohamed Amine ;
Chaabani, Abdellah Mohamed ;
Taleb-Ahmed, Abdelmalik .
2020 IEEE INTERNATIONAL CONFERENCE ON INTERNET OF THINGS AND INTELLIGENCE SYSTEM (IOTAIS), 2021, :23-29
[7]   A Survey of Intrusion Detection Systems in Wireless Sensor Networks [J].
Butun, Ismail ;
Morgera, Salvatore D. ;
Sankar, Ravi .
IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2014, 16 (01) :266-282
[8]  
Chalapathi G.S.S., 2021, Fog/edge Comput. for Secur., P293, DOI DOI 10.1007/978-3-030-57328-7_12
[9]  
Chen H., 2016, RES IMPLEMENTATION I
[10]  
Chen Y., 2017, SERVICE ORIENTED COM, V6th ed.